Netskope Threat Labs

Babar

ATP Sandbox Adv. HeuristicsAV

Babar is a sophisticated backdoor associated with state sponsored espionage groups that provides extensive reconnaissance and data theft capabilities on Windows systems. It can capture keystrokes, record audio, take screenshots, and monitor communications on targeted machines. Researchers have linked it to long running campaigns against governments, diplomatic targets, and other organizations of intelligence interest, and its low profile design emphasizes stealth over mass distribution.

First seen
January 2022
Last seen
October 2026
babar
Alert Name
Binary.Infostealer.Babar
Binary.Trojan.Babar
ByteCode-MSIL.Infostealer.Babar
ByteCode-MSIL.Trojan.Babar
Gen:Variant.Adware.Babar.109
Gen:Variant.Adware.Babar.16862
Gen:Variant.Adware.Babar.16882
Gen:Variant.Adware.Babar.16963
Gen:Variant.Adware.Babar.16965
Gen:Variant.Adware.Babar.16980