Babar

Aliases: SNOWBALL

First seen
2009-01-01 00:00:00
Malware type
spyware, rat
Family
Malware family
Last IoC activity
2026-07-15 20:45:03
Profile updated
2026-07-07 12:47:24

Targeted industries: government-and-public-sector

Targeted regions: country_code:fr country_code:ca

Context

Babar, also known as SNOWBALL, is a sophisticated piece of malware associated with cyber-espionage activities. It has been used to target government and public sector entities, primarily in France and Canada.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Oracrat (yara-rule)
  • MALPEDIA_Win_Babar_Auto (yara-rule)

Reports & references

  • web.archive.org — Babar Suspected Nation State Spyware Spotlight (report)
  • gdatasoftware.com — 24270 Babar Espionage Software Finally Found And Put Under The Microscope (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Babar (report)
  • spiegel.de — Media 35683 (report)
  • researchcenter.paloaltonetworks.com — Unit42 Analysing 10 Year Old Snowball (report)
  • drive.google.com — 0B9Mrr En8Fx4Dzjqlwhdblhseta (report)

External references