Netskope Threat Labs

Tofsee

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Tofsee (a.k.a. Gheg) is a Trojan type program that turns infected Windows systems into multipurpose platforms for criminal activity. It can send spam, conduct distributed denial of service attacks, mine cryptocurrency, and steal stored account credentials, and it keeps itself updated on infected machines. Its operators have mainly used it as an email oriented tool that targets victims' email accounts.

First seen
January 2022
Last seen
October 2026
Alert Name
Backdoor.Tofsee.AM
Backdoor.Tofsee.BB
Backdoor.Tofsee.DW
Backdoor.Tofsee.Gen
Document-Access.Backdoor.Tofsee
Dump:Backdoor.Tofsee.DW
Gen:Variant.Tofsee.1
Win32.Backdoor.Tofsee