Last seven days
- First activity
- Sep 1, 2026
- Last activity
- Sep 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 4 IP / 5 hostnames
Tofsee, also known as Gheg, is a long-running modular Windows botnet malware family primarily associated with spam operations but capable of a broader range of criminal activity.
Profile source: Mallory opens in a new tabTofsee
Tofsee, also known as Gheg, is a long-running modular Windows botnet malware family primarily associated with spam operations but capable of a broader range of criminal activity. Active since at least the late 2000s and widely observed from 2013 onward, it has been used in mass campaigns to build spambots and botnets, send large volumes of unsolicited email, conduct click fraud, proxy traffic, perform cryptocurrency mining, and download additional malware. Some reporting also attributes credential-stealing functionality to the family. Tofsee is commonly described as plugin-based, with a core component that maintains encrypted command-and-control communications, retrieves updated configuration data, and loads DLL-based modules in memory to extend functionality.
Its architecture typically consists of a loader and a core bot component. The loader has been observed masquerading as benign content, including social-media lures, and downloading both the core malware and a decoy file. The core module hides on the infected host, communicates with command-and-control servers over commonly allowed ports using custom encryption rather than standard TLS, and receives frequent configuration updates. Documented plugins support spam delivery, proxying, denial-of-service activity, sniffing, spreading, protective or anti-bot functions, and cryptocurrency mining. Analyses of more recent activity found active use of proxying and miner modules, with infected systems serving as backconnect proxies and participating in privacy-coin mining, while spam functionality remained available even when less prominent in observed telemetry.
Tofsee has been delivered through multiple infection vectors over time. Observed distribution methods include phishing and spearphishing emails with malicious attachments, social-network lures, exploit-kit delivery in earlier campaigns, and installation by third-party malware loaders such as PrivateLoader and HijackLoader. In email-borne campaigns, attachments have included obfuscated script downloaders that retrieve and execute the bot on Windows systems. Once installed, Tofsee has been observed establishing persistence through Windows services, Run-key autostart entries, scheduled or service-based mechanisms, and stored local configuration data. It also employs defense-evasion techniques including packing, code obfuscation, anti-analysis behavior, Windows Defender exclusions, firewall-rule modification, and process injection into legitimate Windows processes such as svchost.exe.
Operationally, infected hosts are used as part of a botnet for spam distribution, click-fraud traffic generation, proxy services, and mining. Spam-related configurations support templated email generation and direct-to-MX delivery, while proxy functionality has been used to relay HTTP(S), SOCKS, and spam-associated traffic. Tofsee has also been linked to broader cybercrime delivery ecosystems in which botnets and loaders are contracted to distribute downstream payloads. The malware has no consistently attributed single threat actor and is better understood as a commodity cybercrime malware family that has evolved through multiple phases while remaining active and periodically resurging in the threat landscape.
C2 tracking
Derp observations, rolling seven-day window
Samples
1d8e433caffa49d0fc9a357ff84cc9217e2cdc2654428f01ddf5c74fd1218a9d 490b92dfd9a41230e2f4b9b2d7544c27b29fb8794f97a5103360ced1db1efc09 4be7942284cf137d138397bd905e7d779d8969efad0d9b88fb29a1d87feb50e3 82c42f530c99f716242e3d456f1b46ac9a7238b292a4e116d4d633b3921b8daa bf47b6b633772d3b5403089abab70a71e65ad38a83beba9a7d5bfe66b4452493 d081ef51068f67456fd1cb26730128adc5e5daf8c77e11f32f74eb0e637005f0 d38f4c8fe3deb6338c561bebe8e7751c97e926907515128a4e579cccebee5ff5 339a97c7c78b458a32c7cf8b8605bbbb70683f8f52ad7d3173dbae72c01ce1a0 9f8fb79da65b653849c5cd56308960bb13357a849eb4f90c830a3634b614a30b b084480eb4af3099db3582cbb5c5bc50afacc0923039ea57b607dd04a0ac46f4 MITRE ATT&CK
Reporting
Researchers reported that the long-running Tofsee botnet, historically known as a modular spambot, was being distributed through the PrivateLoader malware loader tied to the ruzki pay-per-install service. While earlier reporting highlighted Tofsee’s aggressive spam activity, newer observations showed the botnet using infected systems primarily for web traffic proxying and cryptocurrency mining, with only a smaller share of activity linked to spam operations. Analysis of Tofsee’s downloaded components identified active proxy and miner plugins, including HTTP(S) and SOCKS backconnect traffic and some spam-related POST requests routed through likely compromised websites. The mining module was configured to mine Masari (MSR) through fastpool.xyz, and researchers estimated the botnet had generated about 200,000 MSR. Sampled telemetry indicated a global infection footprint, with India accounting for roughly 33% of observed infections in the dataset.
Upatre, a malware downloader commonly spread through phishing emails, was observed using a simple anti-analysis technique to avoid detection in automated sandbox environments. The malware calls the Windows API GetTickCount and terminates if the infected system appears to have been running for less than roughly 12 minutes, a condition that often matches freshly booted virtual machines used for short-lived malware analysis. The evasion tactic can cause Upatre samples to appear benign because they never execute their malicious payload during analysis. Researchers reported a surge in new Upatre samples using the method and noted that the downloader is frequently used to fetch the Dyre banking Trojan, which steals credentials. Palo Alto Networks said its WildFire platform mitigates the trick by modifying the GetTickCount return value so the malware believes the host has been running for hours.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.