TOFSEE
GHEG
SPAM BOTNET
CRYPTOMINER
Threat IntelligenceMalwareJanuary 9, 202615 min read

Tofsee: The Modular Spam Botnet That Mines, DDoSes, and Spreads

Inside the 13-year-old modular botnet that combines industrial-scale spam, cryptocurrency mining, DDoS attacks, and social media worm propagation in a single resilient platform.

Scroll

Tofsee (also known as Gheg) is a modular spam botnet that has been active since May 2013. What sets Tofsee apart from other botnets is its remarkable versatility — combining spam distribution, cryptocurrency mining, DDoS attacks, social media worm propagation, and proxy services in a single modular framework that has survived over a decade of takedown attempts.

Overview & History

Tofsee first appeared in 2013 as a spam-focused botnet, but has continuously evolved by adding pluggable modules that extend its capabilities far beyond email spam. The malware is written in C/C++ and employs process hollowing of svchost.exe as its primary execution technique.

Longevity

Tofsee has been continuously operational for 13+ years, making it one of the longest-running active botnets. Its modular architecture allows operators to adapt to new monetization strategies without rebuilding core infrastructure.

Modular Architecture

Tofsee's power lies in its plugin system. The C2 server delivers modules to bots based on operational needs:

ModuleFunctionDetails
plg_spamSpam EngineHigh-volume SMTP spam with template-based content generation
plg_minerCryptominingMonero (XMR) mining via modified XMRig; ~200K concurrent miners estimated
plg_ddosDDoSHTTP/UDP/TCP flood attacks against specified targets
plg_spreadSocial SpreadingWorm propagation via Facebook, Twitter/X, and Skype messages
plg_antibotAnti-AnalysisDetects and evades security tools, sandboxes, and researchers
proxyRProxy ServiceSOCKS proxy for traffic routing through infected hosts
plg_protectSelf-DefenseRemoves competing malware and protects installation

Technical Analysis

Execution Chain

Anti-Analysis Techniques

Domain Generation Algorithm

DGA Cracked

GovCERT.ch (Swiss CERT) reverse-engineered Tofsee's DGA, enabling predictive domain blocking. The algorithm generates 20 domains per week using .ch and .biz TLDs based on a date-seeded algorithm.

Distribution Methods

MITRE ATT&CK Mapping

TacticTechniqueUsage
ExecutionT1055.012 Process HollowingInjects into svchost.exe
PersistenceT1543.003 Windows ServiceCreates service for hollowed process
Defense EvasionT1562.004 Disable FirewallModifies Windows Firewall rules
Defense EvasionT1497.001 System ChecksVM and sandbox detection
Defense EvasionT1027 Obfuscated FilesXOR string encryption
DiscoveryT1622 Debugger EvasionAnti-debugging checks
Lateral MovementT1091 Replication via MediaUSB worm propagation
ImpactT1496 Resource HijackingMonero cryptocurrency mining
ImpactT1498 Network DoSDDoS flood attacks
C2T1568.002 DGA20 domains/week (.ch/.biz)

Global Scale & Impact

Detection & Defense

Combat Botnet Infrastructure

Mjolnir Security provides comprehensive botnet detection, remediation, and prevention services.

Botnet DetectionDGA MonitoringNetwork ForensicsIncident ResponseMDR ServicesThreat Intelligence
  • Botnet Infrastructure Detection Proactive identification of botnet C2 communication, DGA traffic patterns, and process hollowing indicators within your network.
  • Cryptomining Detection Identify unauthorized cryptocurrency mining activity consuming your compute resources and increasing operational costs.
  • 24/7 Incident Response Rapid containment and remediation of botnet infections across your enterprise. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: January 9, 2026