TOFULOAD is a Windows passive implant associated with the Iranian state-linked threat cluster UNC1860, which is assessed to be affiliated with the Ministry of Intelligence and Security. It is part of a broader UNC1860 toolset used to establish stealthy, long-term access in high-priority Middle Eastern targets, particularly government and telecommunications networks, and appears to be reserved for higher-value intrusions.
TOFULOAD is characterized by passive listener behavior rather than conventional outbound command-and-control. It communicates using undocumented Windows Input/Output Control mechanisms, a design choice intended to reduce visibility to endpoint and network monitoring tools. Reporting also describes it as a TCP-based passive listener and notes that UNC1860 uses such implants to avoid initiating outbound traffic, enabling operators or partnered teams to task compromised systems through inbound connections from intermediary infrastructure or other compromised hosts.
Within UNC1860 intrusion chains, TOFULOAD is deployed after initial compromise achieved through exploitation of vulnerable internet-facing systems and follow-on web shell or dropper activity. It has been observed as a payload loaded and executed by OATBOAT, a loader used by the same actor. The malware fits UNC1860’s broader tradecraft of maintaining covert footholds and facilitating persistent access that can support later operations by UNC1860 or other MOIS-aligned operators.
TOFULOAD reflects a high level of Windows internals knowledge and a deliberate emphasis on defense evasion. Its passive architecture and use of undocumented communication paths distinguish it from more typical backdoors that rely on regular API-driven outbound beaconing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC1860 relies on custom-made passive backdoors like TOFULOAD and WINTAPIX, which leverage undocumented Input/Output Control (IOCTL) commands for communication, bypassing standard detection mechanisms used by EDR systems.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Both passive implants TOFUDRV and TOFULOAD leverage undocumented Input/Output Control commands for communication... using them promises lower detection rates and possibilities akin to filtering drivers, which act as middlemen allowing for the inspection, modification, or blocking of network traffic before it reaches the device or application, as well as assets like file system objects and registry entries.
UNC1860 relies on custom-made passive backdoors like TOFULOAD and WINTAPIX, which leverage undocumented Input/Output Control (IOCTL) commands for communication, bypassing standard detection mechanisms used by EDR systems. These implants operate without initiating outbound traffic, making them difficult to detect through traditional network monitoring tools.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TCP-based passive listener payload loaded by Oatboat, designed for stealthy inbound-only control.
Passive implant using undocumented IOCTL commands for communications.
A custom passive backdoor/implant used by UNC1860 that communicates via undocumented IOCTL commands and avoids initiating outbound traffic, making it difficult to detect through traditional network monitoring.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.