TOFUDRV is a malicious Windows kernel driver associated with the Iranian state-sponsored threat cluster UNC1860, which is assessed to be affiliated with the Ministry of Intelligence and Security. It is part of a broader toolkit used to establish stealthy, long-term access in compromised environments, particularly within government and telecommunications networks in the Middle East. TOFUDRV has been described as overlapping in code and functionality with WINTAPIX and as part of UNC1860’s collection of passive implants designed to minimize conventional command-and-control visibility.
The malware’s tradecraft emphasizes covert post-compromise persistence and defense evasion. Along with TOFULOAD, TOFUDRV uses undocumented IOCTL-based communication, a technique that requires detailed operating system knowledge and can reduce the likelihood of detection by endpoint monitoring products. This places TOFUDRV within UNC1860’s pattern of deploying passive or listener-style implants that avoid initiating obvious outbound traffic, complicating network-based detection and supporting durable access for follow-on operations.
TOFUDRV appears in intrusion chains where UNC1860 first gains access by exploiting vulnerable internet-facing servers and deploying web shells or droppers, after which more specialized implants are installed to maintain access and support later operations. UNC1860 has been linked to operational overlap with APT34 and is assessed to function in part as an initial access provider within the Iranian cyber ecosystem. In that context, TOFUDRV is best understood as a stealth-focused kernel component used after compromise to help preserve access and enable continued operations on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Both passive implants TOFUDRV and TOFULOAD leverage undocumented Input/Output Control commands for communication... using them promises lower detection rates and possibilities akin to filtering drivers, which act as middlemen allowing for the inspection, modification, or blocking of network traffic before it reaches the device or application, as well as assets like file system objects and registry entries.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.