Tofsee is a spam-capable botnet associated with malware delivery operations. It has been observed as part of a service-based cybercrime ecosystem in which botnet operators distribute malicious email at scale while separate actors provide downstream malware staging and delivery. In documented Strela Stealer campaigns, Tofsee was used to originate spam messages that led into a multi-stage infection chain, with first-stage payload hosting handled by infrastructure controlled by another actor. Tofsee has also been linked to propagation via PrivateLoader, indicating its role within broader criminal malware distribution networks. Based on the available facts, Tofsee is best characterized as a financially motivated cybercriminal botnet used primarily for spam-based initial access and malware delivery rather than as a distinct espionage or ransomware actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.