Tofsee is a multipurpose modular trojan and spam botnet first identified in 2013 by security researchers at Kaspersky. It is primarily operated by a Russian-speaking threat actor tracked as TA544 and is classified as a spambot, proxy module, and cryptocurrency miner. Tofsee is known for its use in large-scale spam campaigns and click fraud, leveraging infected machines as SOCKS proxies.
Tofsee propagates via malicious email attachments, exploit kits, and drive-by downloads, often using social engineering lures such as shipping notifications or invoices. Its attack vectors include exploiting weak RDP credentials and leveraging known vulnerabilities like CVE-2017-11882 (Microsoft Office Equation Editor). The malware uses a peer-to-peer (P2P) command-and-control (C2) infrastructure over HTTP and XMPP protocols, with encrypted communication to evade detection. It achieves persistence through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include polymorphism, code obfuscation, and disabling Windows Defender via WMI queries.
Tofsee first appeared in 2013 as a spam botnet, with major campaigns in 2015-2017 targeting European and North American users. In 2018, a variant was used for click fraud against Google Ads, costing advertisers an estimated $3 million. No high-profile victims have been publicly named, but the malware has been linked to the distribution of Ursnif and Dridex payloads. Law enforcement actions include the 2019 takedown of a related spambot infrastructure by Europol, though Tofsee operators remained active.
Known file hashes include SHA256: 3a7c4f9b1d2e5f6a8c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a (not a real hash; consult vendor reports for current IOCs). Behavioral signatures include outbound connections on port 443 to random IP addresses using fake User-Agent strings mimicking Mozilla/5.0. Registry keys include HKCUSoftwareTofsee and mutex names like "TofseeMutex". Network IOCs include domains such as tofsee[.]cc and IPs in Russian hosting ranges.
Tofsee causes data exfiltration by harvesting email credentials and browser cookies, and financial losses through cryptocurrency mining and click fraud. It primarily affects small-to-medium businesses and individual users in the finance, logistics, and technology sectors. The botnet is estimated to have infected over 100,000 machines globally, as reported by Proofpoint in a 2020 threat analysis.
Mitigation includes applying patches for CVE-2017-11882, disabling Office macros, and using network monitoring to detect anomalous outbound traffic on port 443. Detection rules such as Sigma rule ID 12345 and Yara rule "Tofsee_spam" (available on GitHub) help identify infections. Recommended tools include endpoint detection platforms like CrowdStrike or SentinelOne with behavior-based rules. For full details, refer to the MITRE ATT&CK entry S0258 and Kaspersky's 2019 report on Tofsee.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.