{
  "family": "tofsee",
  "sample_count": 264,
  "category": "spam_bot",
  "description": "Tofsee (also known as Gheg) is a multi-purpose Trojan and botnet that is primarily used as an email-oriented tool, targeting victims' email accounts and sending spam. According to analyses such as PCrisk, Tofsee is modular and capable of a wide range of malicious activity, including launching distributed denial-of-service (DDoS) attacks, mining cryptocurrency, sending emails, stealing various account credentials, and updating itself. Because it is modular, an infected machine can be repurposed for several of these tasks. Tofsee is documented by Fraunhofer FKIE's Malpedia.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "gheg"
  ],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What is Tofsee?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Tofsee, also known as Gheg, is a modular Trojan and botnet most commonly used as an email-oriented tool. It targets users' email accounts and is widely associated with sending spam."
      }
    },
    {
      "@type": "Question",
      "name": "What is Tofsee capable of?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Tofsee is modular and can perform a range of malicious actions, including launching DDoS attacks, mining cryptocurrency, sending emails and spam, stealing account credentials, and updating itself with new functionality."
      }
    },
    {
      "@type": "Question",
      "name": "What is the main purpose of Tofsee?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Although it has many capabilities, Tofsee is mainly used as an email-oriented tool that targets victims' email accounts. Having Tofsee installed can, however, lead to additional problems because of its other modules."
      }
    },
    {
      "@type": "Question",
      "name": "What sources document Tofsee?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Tofsee (Gheg) is profiled in Fraunhofer FKIE's Malpedia, and its capabilities have been described in vendor analyses such as those referenced by PCrisk."
      }
    }
  ],
  "faq_count": 4,
  "mitre_attack": [
    "T1071.001",
    "T1547.001"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-06-11",
  "sources": [
    {
      "name": "Malpedia (Fraunhofer FKIE): Tofsee",
      "url": "https://malpedia.caad.fkie.fraunhofer.de/details/win.tofsee"
    },
    {
      "name": "PCrisk: Tofsee (Gheg) Trojan analysis",
      "url": "https://www.pcrisk.com/removal-guides/14534-tofsee-trojan"
    }
  ],
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}