Babar
Aliases: SNOWBALL
- First seen
- 2009-01-01 00:00:00
- Malware type
- spyware, rat
- Family
- Malware family
- Last IoC activity
- 2026-07-15 20:45:03
- Profile updated
- 2026-07-07 12:47:24
Targeted industries: government-and-public-sector
Targeted regions: country_code:fr country_code:ca
Context
Babar, also known as SNOWBALL, is a sophisticated piece of malware associated with cyber-espionage activities. It has been used to target government and public sector entities, primarily in France and Canada.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Oracrat (yara-rule)
- MALPEDIA_Win_Babar_Auto (yara-rule)
Reports & references
- web.archive.org — Babar Suspected Nation State Spyware Spotlight (report)
- gdatasoftware.com — 24270 Babar Espionage Software Finally Found And Put Under The Microscope (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Babar (report)
- spiegel.de — Media 35683 (report)
- researchcenter.paloaltonetworks.com — Unit42 Analysing 10 Year Old Snowball (report)
- drive.google.com — 0B9Mrr En8Fx4Dzjqlwhdblhseta (report)