Here is an example of a Tofsee message body: The attachment is a zip archive named [Sender First Name]that contains a Javascript file.In all cases analyzed, the filename of the javascript file is a woman’s first name.This activity seemed to disappear in June, however Talos has recently observed a marked increase in the volume and velocity of spam email campaigns containing malicious attachments that are being used to distribute Tofsee.

The RIG exploit kit moved from distributing Tofsee to other payloads, possibly because distributing them was more attractive to cybercriminals from a monetization standpoint or simply because different actors began using this exploit kit as a distribution mechanism for their malware.Given the volume of spam messages that infected hosts attempt to distribute, new nodes are quickly added to DNS-based Blackhole Lists (DNSBL) and most of the major email service providers will not accept new message transmissions once this occurs.In order to keep spam levels consistent new nodes must be added constantly.When RIG stopped distributing Tofsee payloads, those responsible for Tofsee switched to alternative distribution methods.

While the Tofsee botnet has been known for sending spam messages, the messages have historically contained links to adult dating and pharmaceutical websites.

Starting in August, Talos began to observe a change in the nature of the spam messages being sent by this botnet.

Each email contains slightly different text, however the same format is used across all of the messages Talos analyzed.