Tofsee

Category: spam_bot · Aliases: gheg · Sample count (EMBER 2018): 264 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

Tofsee, also known as Gheg, is a long-running spambot that infects machines to send pharmaceutical, dating, and cryptocurrency spam. Active since 2008, Tofsee continues to be observed and is notable for its use of peer-to-peer protocols and resilience to takedowns.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1071.001 T1547.001

Frequently Asked Questions

What is Tofsee?

Tofsee, also known as Gheg, is a long-running spambot that infects machines to send pharmaceutical, dating, and cryptocurrency spam. Active since 2008, Tofsee continues to be observed and is notable for its use of peer-to-peer protocols and resilience to takedowns.

How does Tofsee spread?

Tofsee is a multi-purpose botnet spreading through other malware droppers, Skype messages, and exploit kits.

What are the signs of a Tofsee infection?

Outbound spam traffic, click-fraud HTTP requests, and DDoS traffic from the infected host along with AV detections for Tofsee or Gheg are common.

What should I do if I think I have Tofsee on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/tofsee.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.