Threat reportPhishingTL-2026-1245

Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer

mediumACTIVE

Compromised RD Session Host Used to Stage Boots-Themed (TL-2026-1245), also tracked as Boots Phishing Campaign, is a medium-severity phishing campaign, first published 2026-06-15. It has no confirmed attribution, affects Microsoft Remote Desktop Web Access (RDWeb) / RD Gateway / RD Session, maps to 19 MITRE ATT&CK techniques (T1005, T1018, T1021.001), and is covered by 9 detection rules and 34 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
34Indicators of compromise

Key facts for TL-2026-1245

Threat ID
TL-2026-1245
Also known as
Boots Phishing Campaign, Terminal Server Phishing Stager, The Devil, Eight Million Emails, and a Whole Lot of Milk
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
small business, retail, government administration, managed service providers, consumer general public
Target regions
united kingdom, bolivia, romania, Global
Detection rules
9
Indicators of compromise
34

Malware and tooling in Compromised RD Session Host Used to Stage Boots-Themed

Malware and tooling: Gammadyne Mailer, Turbo-Mailer, dracii.mmp (Gammadyne project file)

How Compromised RD Session Host Used to Stage Boots-Themed works

A Romanian-linked operator brute-forced and then logged into an internet-exposed, MFA-less Microsoft RDWeb/RD Gateway portal at a small business using stolen credentials, staged the legitimate bulk-mail tool Gammadyne Mailer on the RD Session Host, and used it to blast phishing emails impersonating UK pharmacy chain Boots to a target list of 8,894,920 addresses. The credential-harvesting payload was hosted on a compromised Bolivian government institute website; Huntress detected the mail-sending burst within minutes, isolated all 25 endpoints on the host, and blocked 29,954 further outbound SMTP connections.

Between 2026-05-13 and 2026-05-16, an internet-facing Microsoft RD Session Host with an exposed RDWeb portal (IIS front end, RD Gateway role enabled, forms-based authentication, no MFA) at a small business was targeted by at least two distinct attacker populations. Over the four days preceding the incident the portal received 657,521 requests from 8,673 distinct IPs, including more than 206,000 login POST attempts (successful logins are distinguishable in IIS logs by an HTTP 302 redirect vs. HTTP 200 for failures). High-volume brute-force bots included 87.251.64.134 (~48,000 requests, no success) and the 88.210.63.0/24 range (~84,000 requests across roughly 10 hosts, no success), both using bare usernames, lowercase portal paths, and generic Go-http-client/2.0 user agents. A separate bot, 216.152.151.168, achieved a single successful login after 127 failed POST attempts on 2026-05-15 21:51 UTC but never pulled a .rdp file or opened a session. A human operator using a browser-realistic client (mixed-case portal paths, domain-qualified usernames, spoofed Mozilla/5.0 user-agent variants, and actual .rdp file retrieval) accessed the portal from Romanian IPs 80.94.95.37 (Timisoara-area hosting, already flagged in threat feeds, first seen 2026-05-13 19:21 UTC) and 212.93.152.37 (Romanian residential fixed-line, first seen 2026-05-15 02:12 UTC). The domain account used validated successfully four separate times across the observed activity (two by the hands-on operator, one by the brute-forcer, one apparent credential-dump hit), consistent with stolen/leaked credentials rather than a software exploit.

The operator's RDP client workstation, tracked in Huntress telemetry as DESKTOP-[REDACTED], had previously been observed across multiple unrelated partner incidents, indicating a shared or rotated attacker toolkit/VM rather than a one-off machine. On 2026-05-16 03:36 UTC the operator (212.93.152.37) reconnected to an existing, disconnected RDP session (session 16) rather than establishing a fresh logon — visible in IIS Event 1315 (forms-auth ticket re-authentication, 03:36:00), RD Gateway Events 312/200/300/302 (tunnel establishment and gateway authentication, 03:36:14), TS-RemoteConnectionManager Event 1149 (RDP authentication success, 03:36:18), and TS-LocalSessionManager Event 25 (session reconnection, 03:36:28). Windows Security auditing on the host was minimal — only two 4624 logon events were recorded in total despite the extensive brute-force and session activity — making the IIS/RDWeb, RD Gateway, and Terminal Services channels the primary source of forensic evidence rather than the Security log.

On the compromised host the operator staged a folder named 'dam pe uk puterniiicccc' (Romanian slang for 'we hit the UK hard') on the desktop, containing the legitimate commercial bulk-mail application Gammadyne Mailer v11.x (gm.exe, digitally signed, zero antivirus detections), a project file named dracii.mmp ('the devils' in Romanian, created 2025-07-18 — roughly ten months before the incident — and last modified 2026-05-16 03:28 UTC) holding sender-spoofing configuration, phishing lure/subject-line templates, and payload URLs, plus six recipient-list text files ('milk (1).txt' through 'milk (6).txt') totaling 8,894,920 email addresses (approximately 1M, 1.33M, 685K, 3.88M, 1M, and 1M addresses respectively). The dracii.mmp configuration also referenced a UNC path to a previously compromised RDS domain (\\[REDACTED].local\RDS\RDSRedirections\...\Crack\gm.log), further indicating the kit had been carried across multiple prior victim terminal servers rather than freshly built for this target. Huntress's broader visibility into the operator's toolkit (via related incidents) showed additional, unused recipient-list themes named for other UK-centric lures — including HMRC (UK tax authority) and Solana cryptocurrency holders — and files with names such as 'fara gmail' (Romanian for 'without Gmail'), indicating an operational rotation of phishing themes rather than a single-campaign toolkit. The mailer was configured for direct-to-MX delivery (performing its own MX lookups and connecting straight to recipient mail servers rather than routing through the victim's own outbound mail relay, and using no DKIM/DomainKeys signing or smart host), with 666 concurrent send threads in 50-message batches, and an operator seed/test address of lacafea77@outlook.com embedded in the Gammadyne configuration. Direct-to-MX delivery both evades mail-provider account throttling and protects the attacker's own sending reputation by burning the victim's IP address instead of a tenant mail domain.

The phishing lure impersonated Boots UK ('boots' <hello@boots.com>), using a merge-field-personalized subject line ('[[-Now-]] Share Your Feedback & Receive a Free Gift from Boots (@bootsUK)... Customer satisfaction survey E-mail:[[-Email-]] NO:[[random_digits(7)]]-[[random_digits(5)]]') driving recipients through a cloned Boots storefront landing page, a throwaway 'customer satisfaction survey' modal, a 'Secure Checkout' form harvesting full name, email, date of birth, phone number, and home address, and a final payment step harvesting payment-card data — all behind a bogus £0.00 order flow and a fake 'Skinny Tan' sponsor tie-in. Seven additional, unused subject-line/body-copy variants were found stored in the kit but never deployed in this run. A cosmetic PGP-signature block (styled HTML text mimicking BEGIN/END PGP SIGNED MESSAGE, Hash: SHA512, and BEGIN/END PGP SIGNATURE, with no actual cryptographic capability) was embedded purely to add visual legitimacy to the phishing page.

Huntress's MDR agent, deployed on the host on 2026-05-15 18:48 UTC (roughly 33 hours before the burst), raised its first critical detection at 2026-05-16 03:38:53 UTC as gm.exe began firing outbound SMTP connections. Over a roughly 104-second window (03:47:03–03:48:47 UTC) the mailer attempted connections to 1,641 distinct MX servers (Google, Microsoft, Yahoo, and regional providers) on TCP/25. The Huntress SOC mass-isolated all 25 endpoints on the customer network via a default-deny filter, flagged the compromised domain account for partner-side reset, severed the active RDP session, blocked further reconnection attempts from 212.93.152.37, and — per Windows Filtering Platform Event 5157 (logging the specific process path \device\harddiskvolume4\users\[user]\desktop\dam pe uk puterniiicccc\gm.exe) — blocked 29,954 additional outbound TCP/25 connection attempts post-isolation. Because delivery was direct-to-MX, the victim's own Microsoft 365/Google mail tenant was never used as a relay, limiting reputational blast radius to the victim's outbound IP rather than its mail domain; the true total of messages successfully sent before isolation cannot be quantified from the available logs, since WFP Event 5157 only captures connections blocked after isolation began. Huntress reported the compromised Bolivian government domain (ipelc.gob.bo, operated by the Instituto Plurinacional de Estudio de Lenguas y Culturas) and its /boots_store/ phishing kit to Centro de Gestión de Incidentes Informáticos (CGII), Bolivia's national CSIRT, coordinated through AGETIC, the country's state ICT agency.

The underlying root cause was a purely configuration-level exposure — an internet-facing RDWeb/RD Gateway portal with no MFA — rather than a software vulnerability, and Gammadyne Mailer itself is legitimate commercial software whose weaponization here is consistent with prior reported abuse of similar bulk-mailers (e.g., Gammadyne Mailer and Turbo-Mailer) by BEC- and phishing-focused actors, including the Nigeria-linked 'TMT' gang, for large-scale direct-to-MX email delivery from compromised infrastructure.

MITRE ATT&CK techniques used in TL-2026-1245

Collection

T1005 Data from Local System; T1114 Email Collection

Discovery

T1018 Remote System Discovery

lateral-movement

T1021.001 Remote Desktop Protocol

Defense Evasion

T1036 Masquerading

Command and Control

T1071.003 Mail Protocols; T1219 Remote Access Tools

Initial Access

T1078.002 Domain Accounts; T1133 External Remote Services; T1566.002 Spearphishing Link

Credential Access

T1110.001 Password Guessing; T1187 Forced Authentication

Execution

T1204.002 Malicious File

Lateral Movement

T1570 Lateral Tool Transfer

Resource Development

T1583.003 Virtual Private Server; T1584.001 Domains; T1584.006 Web Services

Reconnaissance

T1589.002 Email Addresses

reconnaissance

T1598.003 Spearphishing Link

Affected products and versions in Compromised RD Session Host Used to Stage Boots-Themed

  • Microsoft — Remote Desktop Web Access (RDWeb) / RD Gateway / RD Session Host
    Vulnerable versions: Any RDWeb/RD Gateway deployment exposed directly to the internet without MFA
    Fixed in: N/A — requires configuration hardening (MFA, VPN/ZTNA placement), not a software patch

Remediation for Compromised RD Session Host Used to Stage Boots-Themed

Immediate actions

  • Isolate the compromised RD Session Host and any endpoints sharing the compromised domain account
  • Disable/reset the compromised domain account and force credential rotation for all accounts with RDWeb access
  • Block outbound TCP/25 from non-mail-relay hosts, and block the identified attacker IPs (212.93.152.37, 80.94.95.37, 216.152.151.168, 87.251.64.134, 88.210.63.0/24) at the perimeter
  • Remove Gammadyne Mailer (gm.exe), dracii.mmp, and the 'milk (1-6).txt' recipient lists from the staging directory and preserve for forensics
  • Report the compromised payload-hosting domain (ipelc.gob.bo) to the relevant national CSIRT for takedown
  • Search environment-wide for the reused RDP client workstation identifier and the UNC path pattern (...\RDS\RDSRedirections\...\Crack\gm.log) as a pivot for other compromised RDS hosts tied to the same operator

Workarounds

  • If RDWeb cannot be immediately removed from the internet, restrict access via IP allowlisting and require client certificate authentication until MFA/VPN is deployed

Longer-term hardening

  • Remove direct internet exposure of RDWeb/RD Gateway; place behind a VPN or ZTNA/SASE gateway
  • Enforce MFA on all remote-access portals, including RDWeb and RD Gateway
  • Enable and centralize verbose Windows Security auditing (4624/4625) and Terminal Services event logging, forwarded to a SIEM
  • Deploy account lockout / adaptive throttling on RDWeb authentication endpoints to blunt brute-force campaigns
  • Monitor for anomalous high-volume outbound SMTP (TCP/25) from hosts that are not designated mail relays
  • Baseline and alert on execution of commercial bulk-mail utilities (Gammadyne Mailer, Turbo-Mailer, and similar) on non-mail-server endpoints

Weaknesses (CWE) in Compromised RD Session Host Used to Stage Boots-Themed

CWE-287, CWE-307, CWE-521, CWE-778

Timeline of Compromised RD Session Host Used to Stage Boots-Themed

  • Gammadyne Mailer project file dracii.mmp is created (per its internal Gammadyne timestamp), the earliest evidence of campaign tooling preparation, roughly ten months before the incident.
  • Human operator logs into the exposed RDWeb portal and pulls a published .rdp file from source IP 80.94.95.37 (Romania, Timisoara hosting) at 19:21 UTC.
  • A separate brute-force bot at 216.152.151.168 achieves one successful login after 127 failed attempts at 21:51 UTC but never pulls a .rdp file or opens a session.
  • Huntress MDR agent is deployed to the customer's environment at 18:48 UTC, roughly 33 hours before the malicious mail-sending burst.
  • Operator logs into RDWeb portal and pulls a .rdp file from 212.93.152.37 (Romania, residential) at 02:12 UTC, the IP used through the rest of the intrusion.
  • Gammadyne Mailer fires a 104-second burst of connection attempts to 1,641 distinct mail servers between 03:47:03 and 03:48:47 UTC; Huntress SOC isolates all 25 endpoints and blocks the activity in progress, logging 29,954 blocked outbound TCP/25 attempts via Windows Filtering Platform Event 5157.
  • Huntress raises its first critical detection at 03:38:53 UTC as gm.exe begins outbound SMTP activity.
  • Operator (212.93.152.37) reconnects to existing RDP session 16 at 03:36 UTC via IIS Event 1315, RD Gateway Events 312/200/300/302, TS-RemoteConnectionManager Event 1149, and TS-LocalSessionManager Event 25 — not a new logon.
  • Huntress publishes its blog post 'The Devil, Eight Million Emails, and a Whole Lot of Milk', disclosing the incident and reporting the compromised Bolivian government domain to CGII, coordinated via AGETIC.

Sources cited for Compromised RD Session Host Used to Stage Boots-Themed

Detection coverage for TL-2026-1245

As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1245 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
34 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats