SYMBOLCOMMON_NAMEaka. SYNONYMS

SNOWGLOBE  (Back to overview)

aka: ATK8, Animal Farm, Snowglobe

In 2014, researchers at Kaspersky Lab discovered and reported on three zero-days that were being used in cyberattacks in the wild. Two of these zero-day vulnerabilities are associated with an advanced threat actor we call Animal Farm. Over the past few years, Animal Farm has targeted a wide range of global organizations. The group has been active since at least 2009 and there are signs that earlier malware versions were developed as far back as 2007.


Associated Families
win.babar win.casper win.evilbunny

References
2019-01-01Council on Foreign RelationsCyber Operations Tracker
Snowglobe
SNOWGLOBE
2017-09-06Palo Alto Networks Unit 42Dominik Reichel
Analysing a 10-Year-Old SNOWBALL
Babar
2015-07-08InfosecPierluigi Paganini
Animal Farm APT and the Shadow of French Intelligence
SNOWGLOBE
2015-03-06Kaspersky LabsGReAT
Animals in the APT Farm
SNOWGLOBE
2015-03-05ESET ResearchJoan Calvet
Casper Malware: After Babar and Bunny, Another Espionage Cartoon
Casper
2015-02-18G DataG Data
Babar: espionage software finally found and put under the microscope
Evilbunny SNOWGLOBE
2015-02-18Vice MotherboardLorenzo Franceschi-Bicchierai
Meet Babar, a New Malware Almost Certainly Created by France
SNOWGLOBE
2015-02-18CyphortMarion Marschalek
Shooting Elephants
Babar
2015-02-18CyphortMarion Marschalek
Babar: Suspected Nation State Spyware In The Spotlight
Babar Evilbunny SNOWGLOBE
2014-12-16CyphortMarion Marschalek
EvilBunny: Malware Instrumented By Lua
Evilbunny SNOWGLOBE
2011-01-01Spiegel OnlineCSE Canada
SNOWGLOBE: From Discovery to Attribution
Babar

Credits: MISP Project