typeentityconfidencemediumcreated2026-08-11updated2026-08-11malware-familyspambotnetloaderpeinstallerevasion

tofsee

Overview

Tofsee is a spam-botnet malware family historically distributed via exploit kits, malspam, and drive-by downloads. In this corpus it appears as an Inno Setup 6.7.0 installer that encrypts and drops the bot payload at runtime. The outer installer masquerades as a Microsoft ODBC driver pack by a fabricated vendor ("Blacker LLC" / "compager"). First confirmed sample in this knowledge base.

Confidence: medium — OpenCTI labels the sample tofsee, but the outer binary is an installer stub, not the bot itself. The inner payload is encrypted and unconfirmed.

Build Stack

  • Toolchain: Inno Setup 6.7.0 (Delphi / Object Pascal compiler) ^[sample d693570c/strings.txt:7552]
  • Arch: PE32 (x86), Windows GUI subsystem ^[sample d693570c/file.txt]
  • Import Table: Standard IAT intact; delay-imports for kernel32.dll and user32.dll ^[sample d693570c/pefile.txt:DelayImport]
  • Overlay: 8.5 MB encrypted LZMA-compressed Inno Setup archive at offset 0x2B200D ^[sample d693570c/binwalk.txt]
  • Signing: Unsigned ^[sample d693570c/rabin2-info.txt:signed=false]
  • Masquerade: Fabricated version info claiming "Microsoft odbc desktop driver pack 3.5" by "Blacker LLC" ^[sample d693570c/exiftool.json]

Capabilities

  • inno-setup-legitimate-installer-abuse
  • lzma-encrypted-overlay-archive
  • version-info-masquerade
  • delay-import-anti-vm
  • spam-botnet-payload-distribution

Deploy / TTPs

Technique ID Evidence
Masquerading T1036.002 "Microsoft odbc desktop driver pack" by "Blacker LLC" ^[sample d693570c/exiftool.json]
Software Packing T1027.002 Encrypted LZMA(2) Inno Setup archive with embedded key/nonce ^[sample d693570c/strings.txt:7058-7059]
Ingress Tool Transfer T1105 Drops Tofsee payload via legitimate installer framework ^[/intel/analyses/d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4.html]
Virtualization/Sandbox Evasion T1497.001 GetLogicalProcessorInformation delay import suggests CPU-feature anti-VM gate ^[sample d693570c/pefile.txt:634]

Variants / Aliases

  • tofsee — this wiki label (OpenCTI tag)
  • Blacker LLC / compager — observed masquerade identity
  • Inner payload family unconfirmed (encrypted)

Notable Analyses

  • /intel/analyses/d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4.html — d693570c, static-only, Inno Setup 6.7.0, encrypted overlay

Related