Threat reportPhishingTL-2026-1245
Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer
Compromised RD Session Host Used to Stage Boots-Themed (TL-2026-1245), also tracked as Boots Phishing Campaign, is a medium-severity phishing campaign, first published 2026-06-15. It has no confirmed attribution, affects Microsoft Remote Desktop Web Access (RDWeb) / RD Gateway / RD Session, maps to 19 MITRE ATT&CK techniques (T1005, T1018, T1021.001), and is covered by 9 detection rules and 34 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 34Indicators of compromise
Key facts for TL-2026-1245
- Threat ID
- TL-2026-1245
- Also known as
- Boots Phishing Campaign, Terminal Server Phishing Stager, The Devil, Eight Million Emails, and a Whole Lot of Milk
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- small business, retail, government administration, managed service providers, consumer general public
- Target regions
- united kingdom, bolivia, romania, Global
- Detection rules
- 9
- Indicators of compromise
- 34
Malware and tooling in Compromised RD Session Host Used to Stage Boots-Themed
Malware and tooling: Gammadyne Mailer, Turbo-Mailer, dracii.mmp (Gammadyne project file)
How Compromised RD Session Host Used to Stage Boots-Themed works
A Romanian-linked operator brute-forced and then logged into an internet-exposed, MFA-less Microsoft RDWeb/RD Gateway portal at a small business using stolen credentials, staged the legitimate bulk-mail tool Gammadyne Mailer on the RD Session Host, and used it to blast phishing emails impersonating UK pharmacy chain Boots to a target list of 8,894,920 addresses. The credential-harvesting payload was hosted on a compromised Bolivian government institute website; Huntress detected the mail-sending burst within minutes, isolated all 25 endpoints on the host, and blocked 29,954 further outbound SMTP connections.
Between 2026-05-13 and 2026-05-16, an internet-facing Microsoft RD Session Host with an exposed RDWeb portal (IIS front end, RD Gateway role enabled, forms-based authentication, no MFA) at a small business was targeted by at least two distinct attacker populations. Over the four days preceding the incident the portal received 657,521 requests from 8,673 distinct IPs, including more than 206,000 login POST attempts (successful logins are distinguishable in IIS logs by an HTTP 302 redirect vs. HTTP 200 for failures). High-volume brute-force bots included 87.251.64.134 (~48,000 requests, no success) and the 88.210.63.0/24 range (~84,000 requests across roughly 10 hosts, no success), both using bare usernames, lowercase portal paths, and generic Go-http-client/2.0 user agents. A separate bot, 216.152.151.168, achieved a single successful login after 127 failed POST attempts on 2026-05-15 21:51 UTC but never pulled a .rdp file or opened a session. A human operator using a browser-realistic client (mixed-case portal paths, domain-qualified usernames, spoofed Mozilla/5.0 user-agent variants, and actual .rdp file retrieval) accessed the portal from Romanian IPs 80.94.95.37 (Timisoara-area hosting, already flagged in threat feeds, first seen 2026-05-13 19:21 UTC) and 212.93.152.37 (Romanian residential fixed-line, first seen 2026-05-15 02:12 UTC). The domain account used validated successfully four separate times across the observed activity (two by the hands-on operator, one by the brute-forcer, one apparent credential-dump hit), consistent with stolen/leaked credentials rather than a software exploit.
The operator's RDP client workstation, tracked in Huntress telemetry as DESKTOP-[REDACTED], had previously been observed across multiple unrelated partner incidents, indicating a shared or rotated attacker toolkit/VM rather than a one-off machine. On 2026-05-16 03:36 UTC the operator (212.93.152.37) reconnected to an existing, disconnected RDP session (session 16) rather than establishing a fresh logon — visible in IIS Event 1315 (forms-auth ticket re-authentication, 03:36:00), RD Gateway Events 312/200/300/302 (tunnel establishment and gateway authentication, 03:36:14), TS-RemoteConnectionManager Event 1149 (RDP authentication success, 03:36:18), and TS-LocalSessionManager Event 25 (session reconnection, 03:36:28). Windows Security auditing on the host was minimal — only two 4624 logon events were recorded in total despite the extensive brute-force and session activity — making the IIS/RDWeb, RD Gateway, and Terminal Services channels the primary source of forensic evidence rather than the Security log.
On the compromised host the operator staged a folder named 'dam pe uk puterniiicccc' (Romanian slang for 'we hit the UK hard') on the desktop, containing the legitimate commercial bulk-mail application Gammadyne Mailer v11.x (gm.exe, digitally signed, zero antivirus detections), a project file named dracii.mmp ('the devils' in Romanian, created 2025-07-18 — roughly ten months before the incident — and last modified 2026-05-16 03:28 UTC) holding sender-spoofing configuration, phishing lure/subject-line templates, and payload URLs, plus six recipient-list text files ('milk (1).txt' through 'milk (6).txt') totaling 8,894,920 email addresses (approximately 1M, 1.33M, 685K, 3.88M, 1M, and 1M addresses respectively). The dracii.mmp configuration also referenced a UNC path to a previously compromised RDS domain (\\[REDACTED].local\RDS\RDSRedirections\...\Crack\gm.log), further indicating the kit had been carried across multiple prior victim terminal servers rather than freshly built for this target. Huntress's broader visibility into the operator's toolkit (via related incidents) showed additional, unused recipient-list themes named for other UK-centric lures — including HMRC (UK tax authority) and Solana cryptocurrency holders — and files with names such as 'fara gmail' (Romanian for 'without Gmail'), indicating an operational rotation of phishing themes rather than a single-campaign toolkit. The mailer was configured for direct-to-MX delivery (performing its own MX lookups and connecting straight to recipient mail servers rather than routing through the victim's own outbound mail relay, and using no DKIM/DomainKeys signing or smart host), with 666 concurrent send threads in 50-message batches, and an operator seed/test address of lacafea77@outlook.com embedded in the Gammadyne configuration. Direct-to-MX delivery both evades mail-provider account throttling and protects the attacker's own sending reputation by burning the victim's IP address instead of a tenant mail domain.
The phishing lure impersonated Boots UK ('boots' <hello@boots.com>), using a merge-field-personalized subject line ('[[-Now-]] Share Your Feedback & Receive a Free Gift from Boots (@bootsUK)... Customer satisfaction survey E-mail:[[-Email-]] NO:[[random_digits(7)]]-[[random_digits(5)]]') driving recipients through a cloned Boots storefront landing page, a throwaway 'customer satisfaction survey' modal, a 'Secure Checkout' form harvesting full name, email, date of birth, phone number, and home address, and a final payment step harvesting payment-card data — all behind a bogus £0.00 order flow and a fake 'Skinny Tan' sponsor tie-in. Seven additional, unused subject-line/body-copy variants were found stored in the kit but never deployed in this run. A cosmetic PGP-signature block (styled HTML text mimicking BEGIN/END PGP SIGNED MESSAGE, Hash: SHA512, and BEGIN/END PGP SIGNATURE, with no actual cryptographic capability) was embedded purely to add visual legitimacy to the phishing page.
Huntress's MDR agent, deployed on the host on 2026-05-15 18:48 UTC (roughly 33 hours before the burst), raised its first critical detection at 2026-05-16 03:38:53 UTC as gm.exe began firing outbound SMTP connections. Over a roughly 104-second window (03:47:03–03:48:47 UTC) the mailer attempted connections to 1,641 distinct MX servers (Google, Microsoft, Yahoo, and regional providers) on TCP/25. The Huntress SOC mass-isolated all 25 endpoints on the customer network via a default-deny filter, flagged the compromised domain account for partner-side reset, severed the active RDP session, blocked further reconnection attempts from 212.93.152.37, and — per Windows Filtering Platform Event 5157 (logging the specific process path \device\harddiskvolume4\users\[user]\desktop\dam pe uk puterniiicccc\gm.exe) — blocked 29,954 additional outbound TCP/25 connection attempts post-isolation. Because delivery was direct-to-MX, the victim's own Microsoft 365/Google mail tenant was never used as a relay, limiting reputational blast radius to the victim's outbound IP rather than its mail domain; the true total of messages successfully sent before isolation cannot be quantified from the available logs, since WFP Event 5157 only captures connections blocked after isolation began. Huntress reported the compromised Bolivian government domain (ipelc.gob.bo, operated by the Instituto Plurinacional de Estudio de Lenguas y Culturas) and its /boots_store/ phishing kit to Centro de Gestión de Incidentes Informáticos (CGII), Bolivia's national CSIRT, coordinated through AGETIC, the country's state ICT agency.
The underlying root cause was a purely configuration-level exposure — an internet-facing RDWeb/RD Gateway portal with no MFA — rather than a software vulnerability, and Gammadyne Mailer itself is legitimate commercial software whose weaponization here is consistent with prior reported abuse of similar bulk-mailers (e.g., Gammadyne Mailer and Turbo-Mailer) by BEC- and phishing-focused actors, including the Nigeria-linked 'TMT' gang, for large-scale direct-to-MX email delivery from compromised infrastructure.
MITRE ATT&CK techniques used in TL-2026-1245
Collection
T1005 Data from Local System; T1114 Email Collection
Discovery
lateral-movement
T1021.001 Remote Desktop Protocol
Defense Evasion
Command and Control
T1071.003 Mail Protocols; T1219 Remote Access Tools
Initial Access
T1078.002 Domain Accounts; T1133 External Remote Services; T1566.002 Spearphishing Link
Credential Access
T1110.001 Password Guessing; T1187 Forced Authentication
Execution
Lateral Movement
Resource Development
T1583.003 Virtual Private Server; T1584.001 Domains; T1584.006 Web Services
Reconnaissance
reconnaissance
Affected products and versions in Compromised RD Session Host Used to Stage Boots-Themed
- Microsoft — Remote Desktop Web Access (RDWeb) / RD Gateway / RD Session Host
Vulnerable versions: Any RDWeb/RD Gateway deployment exposed directly to the internet without MFA
Fixed in: N/A — requires configuration hardening (MFA, VPN/ZTNA placement), not a software patch
Remediation for Compromised RD Session Host Used to Stage Boots-Themed
Immediate actions
- Isolate the compromised RD Session Host and any endpoints sharing the compromised domain account
- Disable/reset the compromised domain account and force credential rotation for all accounts with RDWeb access
- Block outbound TCP/25 from non-mail-relay hosts, and block the identified attacker IPs (212.93.152.37, 80.94.95.37, 216.152.151.168, 87.251.64.134, 88.210.63.0/24) at the perimeter
- Remove Gammadyne Mailer (gm.exe), dracii.mmp, and the 'milk (1-6).txt' recipient lists from the staging directory and preserve for forensics
- Report the compromised payload-hosting domain (ipelc.gob.bo) to the relevant national CSIRT for takedown
- Search environment-wide for the reused RDP client workstation identifier and the UNC path pattern (...\RDS\RDSRedirections\...\Crack\gm.log) as a pivot for other compromised RDS hosts tied to the same operator
Workarounds
- If RDWeb cannot be immediately removed from the internet, restrict access via IP allowlisting and require client certificate authentication until MFA/VPN is deployed
Longer-term hardening
- Remove direct internet exposure of RDWeb/RD Gateway; place behind a VPN or ZTNA/SASE gateway
- Enforce MFA on all remote-access portals, including RDWeb and RD Gateway
- Enable and centralize verbose Windows Security auditing (4624/4625) and Terminal Services event logging, forwarded to a SIEM
- Deploy account lockout / adaptive throttling on RDWeb authentication endpoints to blunt brute-force campaigns
- Monitor for anomalous high-volume outbound SMTP (TCP/25) from hosts that are not designated mail relays
- Baseline and alert on execution of commercial bulk-mail utilities (Gammadyne Mailer, Turbo-Mailer, and similar) on non-mail-server endpoints
Weaknesses (CWE) in Compromised RD Session Host Used to Stage Boots-Themed
Timeline of Compromised RD Session Host Used to Stage Boots-Themed
- Gammadyne Mailer project file dracii.mmp is created (per its internal Gammadyne timestamp), the earliest evidence of campaign tooling preparation, roughly ten months before the incident.
- Human operator logs into the exposed RDWeb portal and pulls a published .rdp file from source IP 80.94.95.37 (Romania, Timisoara hosting) at 19:21 UTC.
- A separate brute-force bot at 216.152.151.168 achieves one successful login after 127 failed attempts at 21:51 UTC but never pulls a .rdp file or opens a session.
- Huntress MDR agent is deployed to the customer's environment at 18:48 UTC, roughly 33 hours before the malicious mail-sending burst.
- Operator logs into RDWeb portal and pulls a .rdp file from 212.93.152.37 (Romania, residential) at 02:12 UTC, the IP used through the rest of the intrusion.
- Gammadyne Mailer fires a 104-second burst of connection attempts to 1,641 distinct mail servers between 03:47:03 and 03:48:47 UTC; Huntress SOC isolates all 25 endpoints and blocks the activity in progress, logging 29,954 blocked outbound TCP/25 attempts via Windows Filtering Platform Event 5157.
- Huntress raises its first critical detection at 03:38:53 UTC as gm.exe begins outbound SMTP activity.
- Operator (212.93.152.37) reconnects to existing RDP session 16 at 03:36 UTC via IIS Event 1315, RD Gateway Events 312/200/300/302, TS-RemoteConnectionManager Event 1149, and TS-LocalSessionManager Event 25 — not a new logon.
- Huntress publishes its blog post 'The Devil, Eight Million Emails, and a Whole Lot of Milk', disclosing the incident and reporting the compromised Bolivian government domain to CGII, coordinated via AGETIC.
Sources cited for Compromised RD Session Host Used to Stage Boots-Themed
- The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
- Hackers Hijack Terminal Server to Launch 8.9 Million-Email Boots Phishing Campaign
- Fake Boots emails target millions in large phishing campaign
- ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories
- Eviction Strategies Tool — Countermeasure CM0042 (RDP hardening)
- RD Web Access abuse: Fighting back
Detection coverage for TL-2026-1245
As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1245 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.