Tofsee (also known as Gheg) is a modular spam botnet that has been active since May 2013. What sets Tofsee apart from other botnets is its remarkable versatility — combining spam distribution, cryptocurrency mining, DDoS attacks, social media worm propagation, and proxy services in a single modular framework that has survived over a decade of takedown attempts.
Overview & History
Tofsee first appeared in 2013 as a spam-focused botnet, but has continuously evolved by adding pluggable modules that extend its capabilities far beyond email spam. The malware is written in C/C++ and employs process hollowing of svchost.exe as its primary execution technique.
- Primary function: High-volume spam distribution (pharmaceutical, dating, malware delivery)
- Secondary functions: Cryptocurrency mining (Monero), DDoS attacks, social media spreading, traffic proxying
- Architecture: Plugin-based modular system with dynamically loaded functionality
- Resilience: Domain Generation Algorithm (DGA) with .ch and .biz TLDs for C2 failover
- Scale: India accounts for approximately 33% of all infections globally
Tofsee has been continuously operational for 13+ years, making it one of the longest-running active botnets. Its modular architecture allows operators to adapt to new monetization strategies without rebuilding core infrastructure.
Modular Architecture
Tofsee's power lies in its plugin system. The C2 server delivers modules to bots based on operational needs:
| Module | Function | Details |
|---|---|---|
plg_spam | Spam Engine | High-volume SMTP spam with template-based content generation |
plg_miner | Cryptomining | Monero (XMR) mining via modified XMRig; ~200K concurrent miners estimated |
plg_ddos | DDoS | HTTP/UDP/TCP flood attacks against specified targets |
plg_spread | Social Spreading | Worm propagation via Facebook, Twitter/X, and Skype messages |
plg_antibot | Anti-Analysis | Detects and evades security tools, sandboxes, and researchers |
proxyR | Proxy Service | SOCKS proxy for traffic routing through infected hosts |
plg_protect | Self-Defense | Removes competing malware and protects installation |
Technical Analysis
Execution Chain
- Initial execution: Dropper copies itself to
%APPDATA%with a randomized filename - Process hollowing: Creates suspended
svchost.exeprocess, unmaps its memory, and injects Tofsee code T1055.012 - Persistence: Creates a Windows service pointing to the hollowed svchost.exe process T1543.003
- Module loading: Contacts C2 and downloads plugin modules based on bot configuration
- Self-defense: Modifies Windows Firewall rules and blocks access to security vendor update servers T1562.004
Anti-Analysis Techniques
- VM detection: Checks for VMware, VirtualBox, and QEMU artifacts T1497.001
- Debugger detection: Uses
IsDebuggerPresent, timing checks, and hardware breakpoint detection T1622 - String encryption: Custom XOR-based string obfuscation for API calls and C2 addresses T1027
- Competing malware removal: Actively scans for and removes other botnet infections to monopolize the host
Domain Generation Algorithm
GovCERT.ch (Swiss CERT) reverse-engineered Tofsee's DGA, enabling predictive domain blocking. The algorithm generates 20 domains per week using .ch and .biz TLDs based on a date-seeded algorithm.
- Generation rate: 20 domains per week (10 .ch + 10 .biz)
- Seed: Based on current date, providing predictable future domains
- Fallback mechanism: If hardcoded C2 addresses fail, bot falls back to DGA-generated domains
- Registration pattern: Operators pre-register domains days before activation
Distribution Methods
- PrivateLoader PPI: Since 2023, primarily distributed via the PrivateLoader pay-per-install service T1189
- Exploit kits: Historical distribution through RIG and Magnitude exploit kits
- Social media worm:
plg_spreadmodule sends malicious links via compromised Facebook/Skype accounts T1204.001 - USB propagation: Copies to removable drives with autorun functionality T1091
- Bundled software: Embedded in cracked software and freeware bundles
MITRE ATT&CK Mapping
| Tactic | Technique | Usage |
|---|---|---|
| Execution | T1055.012 Process Hollowing | Injects into svchost.exe |
| Persistence | T1543.003 Windows Service | Creates service for hollowed process |
| Defense Evasion | T1562.004 Disable Firewall | Modifies Windows Firewall rules |
| Defense Evasion | T1497.001 System Checks | VM and sandbox detection |
| Defense Evasion | T1027 Obfuscated Files | XOR string encryption |
| Discovery | T1622 Debugger Evasion | Anti-debugging checks |
| Lateral Movement | T1091 Replication via Media | USB worm propagation |
| Impact | T1496 Resource Hijacking | Monero cryptocurrency mining |
| Impact | T1498 Network DoS | DDoS flood attacks |
| C2 | T1568.002 DGA | 20 domains/week (.ch/.biz) |
Global Scale & Impact
- Geographic distribution: India (33%), Indonesia, Brazil, Pakistan, and Vietnam are the most affected countries
- Mining revenue: Estimated ~200,000 concurrent mining bots generating significant Monero revenue
- Spam volume: Capable of sending millions of emails per day across the botnet
- Infrastructure: Multiple C2 tiers with DGA fallback ensure operational continuity
Detection & Defense
- Process hollowing detection: Monitor for svchost.exe instances with unexpected parent processes or memory regions
- DGA domain blocking: Use GovCERT.ch's published DGA algorithm to predictively block future C2 domains
- Mining detection: Monitor for XMRig-related CPU usage spikes and Stratum mining protocol connections
- SMTP anomalies: Detect high-volume outbound SMTP from non-mail-server endpoints
- Firewall rule monitoring: Alert on unauthorized Windows Firewall modifications
- Service creation monitoring: Log and alert on new service installations, especially those pointing to svchost.exe
Combat Botnet Infrastructure
Mjolnir Security provides comprehensive botnet detection, remediation, and prevention services.
- Botnet Infrastructure Detection Proactive identification of botnet C2 communication, DGA traffic patterns, and process hollowing indicators within your network.
- Cryptomining Detection Identify unauthorized cryptocurrency mining activity consuming your compute resources and increasing operational costs.
- 24/7 Incident Response Rapid containment and remediation of botnet infections across your enterprise. Call +1 833 403 5875.
Stay ahead of emerging threats. Get notified when we publish new intelligence reports and advisories.
Subscribe to Alerts