Tofsee, also known as Gheg, is a long-running modular Windows botnet malware family primarily associated with spam operations but capable of a broader range of criminal activity. Active since at least the late 2000s and widely observed from 2013 onward, it has been used in mass campaigns to build spambots and botnets, send large volumes of unsolicited email, conduct click fraud, proxy traffic, perform cryptocurrency mining, and download additional malware. Some reporting also attributes credential-stealing functionality to the family. Tofsee is commonly described as plugin-based, with a core component that maintains encrypted command-and-control communications, retrieves updated configuration data, and loads DLL-based modules in memory to extend functionality.
Its architecture typically consists of a loader and a core bot component. The loader has been observed masquerading as benign content, including social-media lures, and downloading both the core malware and a decoy file. The core module hides on the infected host, communicates with command-and-control servers over commonly allowed ports using custom encryption rather than standard TLS, and receives frequent configuration updates. Documented plugins support spam delivery, proxying, denial-of-service activity, sniffing, spreading, protective or anti-bot functions, and cryptocurrency mining. Analyses of more recent activity found active use of proxying and miner modules, with infected systems serving as backconnect proxies and participating in privacy-coin mining, while spam functionality remained available even when less prominent in observed telemetry.
Tofsee has been delivered through multiple infection vectors over time. Observed distribution methods include phishing and spearphishing emails with malicious attachments, social-network lures, exploit-kit delivery in earlier campaigns, and installation by third-party malware loaders such as PrivateLoader and HijackLoader. In email-borne campaigns, attachments have included obfuscated script downloaders that retrieve and execute the bot on Windows systems. Once installed, Tofsee has been observed establishing persistence through Windows services, Run-key autostart entries, scheduled or service-based mechanisms, and stored local configuration data. It also employs defense-evasion techniques including packing, code obfuscation, anti-analysis behavior, Windows Defender exclusions, firewall-rule modification, and process injection into legitimate Windows processes such as svchost.exe.
Operationally, infected hosts are used as part of a botnet for spam distribution, click-fraud traffic generation, proxy services, and mining. Spam-related configurations support templated email generation and direct-to-MX delivery, while proxy functionality has been used to relay HTTP(S), SOCKS, and spam-associated traffic. Tofsee has also been linked to broader cybercrime delivery ecosystems in which botnets and loaders are contracted to distribute downstream payloads. The malware has no consistently attributed single threat actor and is better understood as a commodity cybercrime malware family that has evolved through multiple phases while remaining active and periodically resurging in the threat landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Talos published a blog post discussing how the RIG exploit kit was delivering this malware to compromised endpoints using malvertising.
Around 3% of the requests were HTTP POST with the URI ending in '.php' and, in many cases, starting with '/wp-', to random websites that appear legitimate... These indicators lead us to believe that these (apparently) legitimate websites have been likely compromised to be used to distribute spam.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
At the first step, we see how it launches a copy of itself to SysWow64 which it then moves to a temporary folder, the commands used, launched by cmd.exe are the following
In addition, we can see, that it enters it in exclusions in registry key, being the path with random name the place where it was previously self-dropped
<HKLM>\SYSTEM\CONTROLSET001\SERVICES\<random, matching '[A-Z0-9]{8}'> 12
While all the above processes are being launched, we have the other binary in a temporary path performing other actions, such as injecting an svchost... Once in this phase, you have the Tofsee functionalities inside a legitimate process
<HKLM>\SYSTEM\CONTROLSET001\SERVICES\<random, matching '[A-Z0-9]{8}'> 12
After this, it creates a service using sc.exe... The command used, launched by sc.exe is as follows: "C:\Windows\System32\sc.exe" create <Name of file dropped> ... start= auto DisplayName= "wifi support"
The code in javascript attachment is obfuscated in an attempt to make analysis more difficult.
The samples are packed but can be easily unpacked... Threat Actors make use of packers when distributing their malware as they remain an effective way to evade detection.
Usually, the file comes from a social network and disguises itself as an interesting picture.
While all the above processes are being launched, we have the other binary in a temporary path performing other actions, such as injecting an svchost... Once in this phase, you have the Tofsee functionalities inside a legitimate process
It also deletes the initial binary using a batch file that is temporarily stored inside the %TEMP% directory.
Although the core module connects to the C&C server through ports 443, 995 or 465, the connections are not standard SSL. The streams between them are encrypted by a customized encryption routine.
the malware downloads two types of resources (updates) from its command-and-control (C2) server: configurations, and plugins to extend its functionality.
Additionally, HTTP GET requests are generated periodically as the malware attempts to simulate clicking on ads as part of its click fraud routine.
Once infected, systems will begin connecting to various SMTP relays and sending spam email messages.
Bitsight has noticed Tofsee engaging in web traffic proxying... and also performing cryptocurrency mining.
192 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet referenced as part of the commodity malware pipeline and observed dropping follow-up payloads.
Malware that distributes spam or phishing messages and can deliver secondary payloads over SMTP/port 25.
An additional malware family embedded in samples delivered through the PrivateLoader distribution chain.
Botnet used to originate/distribute spam emails in the described campaigns; historically propagated via the PrivateLoader loader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.