APTMembers
APT

Decade-Old Tofsee Payload Masquerades as Windows Driver partmgr.sys

A 10MB Win32 dropper compiled in 2014 but not seen until 2019 borrows the filename of a legitimate disk-partition driver while cycling through disposable installer names. Three sandboxes unanimously flagged it malicious despite a built-in CPU-timer anti-analysis check, and 65 of 76 AV engines now detect it.

Sep 24, 2026, 15:31 (UTC+9)Last seenSep 25, 2026Severity74ByCTX TeamActorSmoky SpiderIOC4MITRE33RegionsCHNL

A 10,878-kilobyte Win32 executable circulates under the file path of a legitimate Windows disk-partition driver — c:\windows\system32\drivers\partmgr.sys — while its delivery names rotate through disposable installer strings such as 89UlgiO5LXmpwSOaII.exe and 8krHNSKndIeDU5GFnJECrkOs.exe. VirusTotal resolves the binary (456d4a6d6f…, hereafter the partmgr.sys impersonator) to trojan.tofsee/dump, and 65 of 76 antivirus engines currently flag it.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence