This activity has increased in velocity and volume.
The filename and hash changes across groups of emails with several being sent on any given day.
When RIG stopped distributing Tofsee payloads, those responsible for Tofsee switched to alternative distribution methods.
While the Tofsee botnet has been known for sending spam messages, the messages have historically contained links to adult dating and pharmaceutical websites.
The phishing emails purport to be from women in Eastern Europe (namely Russia and Ukraine) and the theme of the emails is adult dating.
Each email contains slightly different text, however the same format is used across all of the messages Talos analyzed.