Casper is a Windows implant associated with long-running espionage activity and has been linked to both the Animal Farm malware ecosystem and separate reporting on TICK operations, indicating that the name has been used for distinct malware in different vendor taxonomies. In the Animal Farm context, Casper is a validator-style reconnaissance implant used to profile newly compromised systems and determine whether they merit follow-on deployment of more capable espionage platforms. It has been observed in watering-hole operations, including attacks leveraging Flash zero-day exploits against visitors to a Syrian government website. Its reconnaissance functions include collecting host and operating system details, architecture, default browser information, running processes, autorun entries, and installed applications. Animal Farm has targeted a broad range of victims, including government entities, military contractors, humanitarian organizations, private companies, journalists, media organizations, and activists.
Separate reporting also uses the name Casper for malware associated with the China-linked espionage group TICK, also known as BRONZE BUTLER. In that usage, Casper is described as a modified Cobalt Strike backdoor employed in Operation ENDTRADE against defense, aerospace, chemical, and satellite organizations with ties to Japan and China. That malware used DLL sideloading and shellcode injection into a system process to evade detection.
Because the same name is applied to different implants across reporting, Casper should be treated as an overloaded malware name rather than a single uniformly defined family. The strongest consistently supported characterization in the supplied material is the Animal Farm variant: a reconnaissance-focused Windows implant used in watering-hole-driven espionage operations to validate and profile targets for subsequent compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Researchers from Kaspersky have reported on the watering hole and two zero-day exploits that were involved [8]... [8] New Flash Player 0-day (CVE-2014-0515) used in watering-hole attacks. | Casper... is so-called reconnaissance malware, used to collect data from an infected machine in order to identify the owner and/or machine-specific settings... Casper is known to have been spread through a watering hole attack... Two Flash zero-day exploits were involved in spreading Casper to potential targets.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Casper – the most recent “validator”-style implant from the Animal Farm group.
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Casper then goes on to collect information about the target system, including the following: • Running processes
All three of these URLs served as C&C contacts, sending commands or Lua scripts to the infected host... Can send and receive files via HTTP... Plainly spoken, Casper is reconnaissance malware aiming to gather sensitive information about the target system and loading second-stage malware should the target be of interest.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE BUTLER threat profile.
A modified Cobalt Strike-based backdoor used by TICK, often hidden in steganographic images, employing DLL sideloading and shellcode injection into svchost.exe to evade antivirus detection.
Another implant in the same ecosystem; mentioned as structurally similar to Babar and likely based on it.
The most recent validator-style implant from Animal Farm, deployed via a watering-hole attack in Syria.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.