Researchers analyzed a 2007 sample of Babar, also known as SNOWBALL, and found it to be an early component of the Animal Farm espionage toolkit. The malware consisted of a loader and payload DLL, used RC4-encrypted configuration data, persisted through Windows Run registry keys, injected into Internet Explorer, and contacted a command-and-control server hosted on a compromised third-party website. It gathered victim system information, stored encrypted identifiers in the registry, and supported remote actions including file download, process listing and termination, reboot, shutdown, and self-removal.
The findings push back the known history of Babar by several years and reinforce its connection to the broader Animal Farm operation previously tied to global espionage activity. Kaspersky had described Animal Farm as a long-running threat actor targeting governments, military contractors, humanitarian groups, companies, journalists, media outlets, and activists, with malware families including Bunny, Dino, Babar, NBot, Tafacalou, and Casper. The older SNOWBALL sample shared similarities with the Casper implant, while researchers also noted a coding bug and a design flaw in the early Babar variant, exposing weaknesses not usually associated with a mature intelligence-grade platform.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
In September 2017, Palo Alto Networks published analysis of a 10-year-old Babar/SNOWBALL sample, documenting its loader, payload, persistence, RC4-encrypted configuration, and use of a compromised third-party website for command and control. The analysis established that this Babar variant predated previously known 2011 samples.
In March 2015, Kaspersky published a report grouping Animal Farm malware into six major families: Bunny, Dino, Babar, NBot, Tafacalou, and Casper. The report described the actor as a long-running espionage group targeting governments, contractors, NGOs, companies, journalists, media, and activists worldwide.
Kaspersky reported in 2014 that three zero-day vulnerabilities were being exploited in the wild and associated two of them with the Animal Farm threat actor. This connected the group to active zero-day operations.
Kaspersky described Bunny as an older validator-style Trojan used by Animal Farm in a PDF zero-day attack in 2011. This tied one of the toolkit's earlier malware families to a specific exploitation campaign.
Kaspersky said the Animal Farm espionage group had been active since at least 2009. The report also noted signs that some earlier malware versions may have been developed as far back as 2007.
Palo Alto Networks analyzed a Babar (SNOWBALL) loader and payload DLL whose compilation timestamps were both on November 9, 2007, showing the malware family existed earlier than previously documented 2011 samples. The sample was identified as an early tool in the Animal Farm toolkit.
During its investigation, Kaspersky sinkholed a large number of Animal Farm command-and-control servers and used Tafacalou infection logs to identify victims across numerous countries. The findings showed Tafacalou acted as an entry-stage implant that could lead to deployment of Babar or Dino.
Kaspersky said the Casper Trojan was the most recent validator-style implant from Animal Farm and that it had been deployed in a watering-hole attack in Syria. The report did not provide a more precise date for that operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.