Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer — Threadlinqs Intelligence
As of 2026-07-11, Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer is a medium-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1245 · Severity: MEDIUM · Status: ACTIVE · Category: PHISHING
A Romanian-linked operator brute-forced and then logged into an internet-exposed, MFA-less Microsoft RDWeb/RD Gateway portal at a small business using stolen credentials, staged the legitimate
Between 2026-05-13 and 2026-05-16, an internet-facing Microsoft RD Session Host with an exposed RDWeb portal (IIS front end, RD Gateway role enabled, forms-based authentication, no MFA) at a small business was targeted by at least two distinct attacker populations. Over the four days preceding the incident the portal received 657,521 requests from 8,673 distinct IPs, including more than 206,000 login POST attempts (successful logins are distinguishable in IIS logs by an HTTP 302 redirect vs. HTTP 200 for failures). High-volume brute-force bots included 87.251.64.134 (~48,000 requests, no success) and the 88.210.63.0/24 range (~84,000 requests across roughly 10 hosts, no success), both using bare usernames, lowercase portal paths, and generic Go-http-client/2.0 user agents. A separate bot, 216.152.151.168, achieved a single successful login after 127 failed POST attempts on 2026-05-15 21:51 UTC but never pulled a .rdp file or opened a session. A human operator using a browser-realistic client (mixed-case portal paths, domain-qualified usernames, spoofed Mozilla/5.0 user-agent variants, and actual .rdp file retrieval) accessed the portal from Romanian IPs 80.94.95.37 (Timisoara-area hosting, already flagged in threat feeds, first seen 2026-05-13 19:21 UTC) and 212.93.152.37 (Romanian residential fixed-line, first seen 2026-05-15 02:12 UTC). The domain account used validated successfully four separate times across the observed activity (two by the hands-on operator, one by the brute-forcer, one apparent credential-dump hit), consistent with stolen/leaked credentials rather than a software exploit.
The operator's RDP client workstation, tracked in Huntress telemetry as DESKTOP-[REDACTED], had previously been observed across multiple unrelated partner incidents, indicating a shared or rotated attacker toolkit/VM rather than a one-off machine. On 2026-05-16 03:36 UTC the operator (212.93.152.37) reconnected to an existing, disconnected RDP session (session 16) rather than establishing a fresh logon — visible in IIS Event 1315 (forms-auth ticket re-authentication, 03:36:00), RD Gateway Events 312/200/300/302 (tunnel establishment and gateway authentication, 03:36:14), TS-RemoteConnectionManager Event 1149 (RDP authentication success, 03:36:18), and TS-LocalSessionManager Event 25 (session reconnection, 03:36:28). Windows Security auditing on the host was minimal — only two 4624 logon events were recorded in total despite the extensive brute-force and session activity — making the IIS/RDWeb, RD Gateway, and Terminal Services channels the primary source of forensic evidence rather than the Security log.
On the compromised host the operator staged a folder named 'dam pe uk puterniiicccc' (Romanian slang for 'we hit the UK hard') on the desktop, containing the legitimate commercial bulk-mail application Gammadyne Mailer v11.x (gm.exe, digitally signed, zero antivirus detections), a project file named dracii.mmp ('the devils' in Romanian, created 2025-07-18 — roughly ten months before the incident — and last modified 2026-05-16 03:28 UTC) holding sender-spoofing configuration, phishing lure/subject-line templates, and payload URLs, plus six recipient-list text files ('milk (1).txt' through 'milk (6).txt') totaling 8,894,920 email addresses (approximately 1M, 1.33M, 685K, 3.88M, 1M, and 1M addresses respectively). The dracii.mmp configuration also referenced a UNC path to a previously compromised RDS domain (\\[REDACTED].local\RDS\RDSRedirections\...\Crack\gm.log), further indicating the kit had been carried across multiple prior victim terminal servers rather than freshly built for this target. Huntress's broader visibility into the operator's toolkit (via related incidents) showed additional, unused recipient-list themes named for other UK-centric lures — including HMRC (UK tax authority) and Solana cryptocurrency holders — and files with names such as 'fara gmail' (Romanian for 'without Gmail'), indicating an operational rotation of p
Weaknesses (CWE)
CWE-287, CWE-307, CWE-521, CWE-778
Target sectors: small business, retail, government administration, managed service providers, consumer general public
Target regions: united kingdom, bolivia, romania, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1583.003, T1584.001, T1584.006, T1589.002, T1110.001, T1187, T1078.002, T1133, T1566.002, T1598.003