Researchers reported that the long-running Tofsee botnet, historically known as a modular spambot, was being distributed through the PrivateLoader malware loader tied to the ruzki pay-per-install service. While earlier reporting highlighted Tofsee’s aggressive spam activity, newer observations showed the botnet using infected systems primarily for web traffic proxying and cryptocurrency mining, with only a smaller share of activity linked to spam operations.
Analysis of Tofsee’s downloaded components identified active proxy and miner plugins, including HTTP(S) and SOCKS backconnect traffic and some spam-related POST requests routed through likely compromised websites. The mining module was configured to mine Masari (MSR) through fastpool.xyz, and researchers estimated the botnet had generated about 200,000 MSR. Sampled telemetry indicated a global infection footprint, with India accounting for roughly 33% of observed infections in the dataset.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Bitsight's sampled telemetry indicated Tofsee infections were distributed worldwide in March 2023, with India accounting for about 33% of observed infections.
Bitsight observed Tofsee being distributed in January 2023 by the PrivateLoader malware loader, which it linked to the ruzki pay-per-install service.
Bitsight found Google references to the Masari miner wallet address used by Tofsee dating back to June 2022, indicating mining-related infrastructure was in use by then.
Bitsight described Tofsee, also known as Gheg, as a long-running modular spambot that has been active since at least 2008.
Bitsight released indicators of compromise, a YARA rule, a Python string decryption example, and Suricata rules for detecting Tofsee malware and its command-and-control traffic.
Through analysis of the active miner plugin and its configured wallet, Bitsight estimated the botnet had mined about 200,000 Masari, worth roughly $1,500 at the time of reporting.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 104 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
bitsight.com
Open sourceblog.talosintelligence.com
Open sourcevirusbulletin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.