Tofsee

Aliases: Gheg

First seen
2013-01-01 00:00:00
Malware type
trojan, botnet, credential-stealer, ddos, cryptominer
Family
Malware family
Last IoC activity
2026-07-22 02:08:31
Profile updated
2026-07-07 13:46:42

Targeted industries: financial-services technology-and-telecommunications professional-services

Context

According to PCrisk, Tofsee (also known as Gheg) is a malicious Trojan-type program that is capable of performing DDoS attacks, mining cryptocurrency, sending emails, stealing various account credentials, updating itself, and more. Cyber criminals mainly use this program as an email-oriented tool (they target users' email accounts), however, having Tofsee installed can also lead to many other problems.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Tofsee (yara-rule)
  • MALPEDIA_Win_Tofsee_Auto (yara-rule)

Related threat objects

  • Gheg (infrastructure)

Reports & references

  • intel471.com — Privateloader Malware (report)
  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
  • blog.checkpoint.com — March 2023S Most Wanted Malware New Emotet Campaign Bypasses Microsoft Blocks To Distribute Malicious Onenote Files (report)
  • Cisco Talos — Threat Roundup 0204 0211 (report)
  • lokalhost.pl — Peering.Into.Spam.Botnets.Virusbulletin2017 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Tofsee (report)
  • web.archive.org — Gheg,Spambot.897~ (report)
  • spamhaus.com — Neutralizing Tofsee Spambot Part 2 Inmemoryconfig Store Vaccine (report)
  • spamhaus.com — Neutralizing Tofsee Spambot Part 3 Network Based Kill Switch (report)
  • dragos.com — Investigating The Watering Hole Linked To The Oldsmar Water Treatment Facility Breach (report)
  • cert.pl — Tofsee En (report)
  • gist.github.com — 0Ec24D7B294248C51De0C3335802Cbd4 (report)
  • bitsight.com — Tofsee Botnet Proxying And Mining (report)
  • zerophagemalware.com — Terror Ek Delivers Tofsee Spambot (report)
  • virusbulletin.com — Tofsee Botnet (report)
  • govcert.ch — Tofsee Spambot Features .Ch Dga Reversal And Countermesaures (report)
  • cert.pl — A Deeper Look At Tofsee Modules (report)
  • spamhaus.com — Neutralizing Tofsee Spambot Part 1 Binary File Vaccine (report)
  • Cisco Talos — Tofsee Spam (report)

External references