Skip to content

Tofsee

Tofsee, also known as Gheg, is a long-running modular Windows botnet malware family primarily associated with spam operations but capable of a broader range of criminal activity.

Profile source: Mallory opens in a new tab

Tofsee

Family profile

Tofsee, also known as Gheg, is a long-running modular Windows botnet malware family primarily associated with spam operations but capable of a broader range of criminal activity. Active since at least the late 2000s and widely observed from 2013 onward, it has been used in mass campaigns to build spambots and botnets, send large volumes of unsolicited email, conduct click fraud, proxy traffic, perform cryptocurrency mining, and download additional malware. Some reporting also attributes credential-stealing functionality to the family. Tofsee is commonly described as plugin-based, with a core component that maintains encrypted command-and-control communications, retrieves updated configuration data, and loads DLL-based modules in memory to extend functionality.

Its architecture typically consists of a loader and a core bot component. The loader has been observed masquerading as benign content, including social-media lures, and downloading both the core malware and a decoy file. The core module hides on the infected host, communicates with command-and-control servers over commonly allowed ports using custom encryption rather than standard TLS, and receives frequent configuration updates. Documented plugins support spam delivery, proxying, denial-of-service activity, sniffing, spreading, protective or anti-bot functions, and cryptocurrency mining. Analyses of more recent activity found active use of proxying and miner modules, with infected systems serving as backconnect proxies and participating in privacy-coin mining, while spam functionality remained available even when less prominent in observed telemetry.

Tofsee has been delivered through multiple infection vectors over time. Observed distribution methods include phishing and spearphishing emails with malicious attachments, social-network lures, exploit-kit delivery in earlier campaigns, and installation by third-party malware loaders such as PrivateLoader and HijackLoader. In email-borne campaigns, attachments have included obfuscated script downloaders that retrieve and execute the bot on Windows systems. Once installed, Tofsee has been observed establishing persistence through Windows services, Run-key autostart entries, scheduled or service-based mechanisms, and stored local configuration data. It also employs defense-evasion techniques including packing, code obfuscation, anti-analysis behavior, Windows Defender exclusions, firewall-rule modification, and process injection into legitimate Windows processes such as svchost.exe.

Operationally, infected hosts are used as part of a botnet for spam distribution, click-fraud traffic generation, proxy services, and mining. Spam-related configurations support templated email generation and direct-to-MX delivery, while proxy functionality has been used to relay HTTP(S), SOCKS, and spam-associated traffic. Tofsee has also been linked to broader cybercrime delivery ecosystems in which botnets and loaders are contracted to distribute downstream payloads. The malware has no consistently attributed single threat actor and is better understood as a commodity cybercrime malware family that has evolved through multiple phases while remaining active and periodically resurging in the threat landscape.

Capabilities

  • Credential Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 1, 2026
Last activity
Sep 7, 2026
Feed role
C2 / Distribution
Host form
4 IP / 5 hostnames

Leading locations

  • DE3
  • SG2
  • ES1
  • HK1
  • SI1

Leading providers

  • FEMO IT SOLUTIONS LIMITED3
  • Google LLC2
  • MYTEK TRADING PTY LTD1
  • VPS Dedicated LLC1
  • ZhouyiSat Communications1

Infrastructure traits

  • Hosting 8

Samples

Recent associated samples

MITRE ATT&CK

Tofsee in ATT&CK

37 distinct techniques

Reporting

Research mentioning Tofsee

Mar 27
Bitsight

Tofsee Botnet: Proxying and Mining | Bitsight

Researchers reported that the long-running Tofsee botnet, historically known as a modular spambot, was being distributed through the PrivateLoader malware loader tied to the ruzki pay-per-install service. While earlier reporting highlighted Tofsee’s aggressive spam activity, newer observations showed the botnet using infected systems primarily for web traffic proxying and cryptocurrency mining, with only a smaller share of activity linked to spam operations. Analysis of Tofsee’s downloaded components identified active proxy and miner plugins, including HTTP(S) and SOCKS backconnect traffic and some spam-related POST requests routed through likely compromised websites. The mining module was configured to mine Masari (MSR) through fastpool.xyz, and researchers estimated the botnet had generated about 200,000 MSR. Sampled telemetry indicated a global infection footprint, with India accounting for roughly 33% of observed infections in the dataset.

Jul 13
Paloalto Researchcenter Historic

Upatre Continued to Evolve with new Anti-Analysis Techniques

Upatre, a malware downloader commonly spread through phishing emails, was observed using a simple anti-analysis technique to avoid detection in automated sandbox environments. The malware calls the Windows API GetTickCount and terminates if the infected system appears to have been running for less than roughly 12 minutes, a condition that often matches freshly booted virtual machines used for short-lived malware analysis. The evasion tactic can cause Upatre samples to appear benign because they never execute their malicious payload during analysis. Researchers reported a surge in new Upatre samples using the method and noted that the downloader is frequently used to fetch the Dyre banking Trojan, which steals credentials. Palo Alto Networks said its WildFire platform mitigates the trick by modifying the GetTickCount return value so the malware believes the host has been running for hours.

Sep 29
Talosintelligence Other

Want Tofsee My Pictures? A Botnet Gets Aggressive

Oct 6
Palo Alto Networks Unit 42

Ticked Off: Upatre Malware’s Simple Anti-analysis Trick to Defeat Sandboxes

Apr 2
Virusbulletin

Virus Bulletin :: Tofsee botnet

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.