
Decade-Old Tofsee Payload Masquerades as Windows Driver partmgr.sys
A 10MB Win32 dropper compiled in 2014 but not seen until 2019 borrows the filename of a legitimate disk-partition driver while cycling through disposable installer names. Three sandboxes unanimously flagged it malicious despite a built-in CPU-timer anti-analysis check, and 65 of 76 AV engines now detect it.
A 10,878-kilobyte Win32 executable circulates under the file path of a legitimate Windows disk-partition driver — c:\windows\system32\drivers\partmgr.sys — while its delivery names rotate through disposable installer strings such as 89UlgiO5LXmpwSOaII.exe and 8krHNSKndIeDU5GFnJECrkOs.exe. VirusTotal resolves the binary (456d4a6d6f…, hereafter the partmgr.sys impersonator) to trojan.tofsee/dump, and 65 of 76 antivirus engines currently flag it.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read