# Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer

> A Romanian-linked operator brute-forced and then logged into an internet-exposed, MFA-less Microsoft RDWeb/RD Gateway portal at a small business using stolen credentials, staged the legitimate bulk-mail tool Gammadyne Mailer on the RD Session Host, and used it to blast phishing emails impersonating UK pharmacy chain Boots to a target list of 8,894,920 addresses. The credential-harvesting payload was hosted on a compromised Bolivian government institute website; Huntress detected the mail-sending burst within minutes, isolated all 25 endpoints on the host, and blocked 29,954 further outbound SMTP connections.

- **Published:** 2026-06-15T00:00:00Z
- **Last reviewed:** 2026-06-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1245
- **ID:** TL-2026-1245
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Between 2026-05-13 and 2026-05-16, an internet-facing Microsoft RD Session Host with an exposed RDWeb portal (IIS front end, RD Gateway role enabled, forms-based authentication, no MFA) at a small business was targeted by at least two distinct attacker populations. Over the four days preceding the incident the portal received 657,521 requests from 8,673 distinct IPs, including more than 206,000 login POST attempts (successful logins are distinguishable in IIS logs by an HTTP 302 redirect vs. HTTP 200 for failures). High-volume brute-force bots included 87.251.64.134 (~48,000 requests, no success) and the 88.210.63.0/24 range (~84,000 requests across roughly 10 hosts, no success), both using bare usernames, lowercase portal paths, and generic Go-http-client/2.0 user agents. A separate bot, 216.152.151.168, achieved a single successful login after 127 failed POST attempts on 2026-05-15 21:51 UTC but never pulled a .rdp file or opened a session. A human operator using a browser-realistic client (mixed-case portal paths, domain-qualified usernames, spoofed Mozilla/5.0 user-agent variants, and actual .rdp file retrieval) accessed the portal from Romanian IPs 80.94.95.37 (Timisoara-area hosting, already flagged in threat feeds, first seen 2026-05-13 19:21 UTC) and 212.93.152.37 (Romanian residential fixed-line, first seen 2026-05-15 02:12 UTC). The domain account used validated successfully four separate times across the observed activity (two by the hands-on operator, one by the brute-forcer, one apparent credential-dump hit), consistent with stolen/leaked credentials rather than a software exploit.

The operator's RDP client workstation, tracked in Huntress telemetry as DESKTOP-[REDACTED], had previously been observed across multiple unrelated partner incidents, indicating a shared or rotated attacker toolkit/VM rather than a one-off machine. On 2026-05-16 03:36 UTC the operator (212.93.152.37) reconnected to an existing, disconnected RDP session (session 16) rather than establishing a fresh logon — visible in IIS Event 1315 (forms-auth ticket re-authentication, 03:36:00), RD Gateway Events 312/200/300/302 (tunnel establishment and gateway authentication, 03:36:14), TS-RemoteConnectionManager Event 1149 (RDP authentication success, 03:36:18), and TS-LocalSessionManager Event 25 (session reconnection, 03:36:28). Windows Security auditing on the host was minimal — only two 4624 logon events were recorded in total despite the extensive brute-force and session activity — making the IIS/RDWeb, RD Gateway, and Terminal Services channels the primary source of forensic evidence rather than the Security log.

On the compromised host the operator staged a folder named 'dam pe uk puterniiicccc' (Romanian slang for 'we hit the UK hard') on the desktop, containing the legitimate commercial bulk-mail application Gammadyne Mailer v11.x (gm.exe, digitally signed, zero antivirus detections), a project file named dracii.mmp ('the devils' in Romanian, created 2025-07-18 — roughly ten months before the incident — and last modified 2026-05-16 03:28 UTC) holding sender-spoofing configuration, phishing lure/subject-line templates, and payload URLs, plus six recipient-list text files ('milk (1).txt' through 'milk (6).txt') totaling 8,894,920 email addresses (approximately 1M, 1.33M, 685K, 3.88M, 1M, and 1M addresses respectively). The dracii.mmp configuration also referenced a UNC path to a previously compromised RDS domain (\\[REDACTED].local\RDS\RDSRedirections\...\Crack\gm.log), further indicating the kit had been carried across multiple prior victim terminal servers rather than freshly built for this target. Huntress's broader visibility into the operator's toolkit (via related incidents) showed additional, unused recipient-list themes named for other UK-centric lures — including HMRC (UK tax authority) and Solana cryptocurrency holders — and files with names such as 'fara gmail' (Romanian for 'without Gmail'), indicating an operational rotation of phishing themes rather than a single-campaign toolkit. The mailer was configured for direct-to-MX delivery (performing its own MX lookups and connecting straight to recipient mail servers rather than routing through the victim's own outbound mail relay, and using no DKIM/DomainKeys signing or smart host), with 666 concurrent send threads in 50-message batches, and an operator seed/test address of lacafea77@outlook.com embedded in the Gammadyne configuration. Direct-to-MX delivery both evades mail-provider account throttling and protects the attacker's own sending reputation by burning the victim's IP address instead of a tenant mail domain.

The phishing lure impersonated Boots UK ('boots' <hello@boots.com>), using a merge-field-personalized subject line ('[[-Now-]] Share Your Feedback & Receive a Free Gift from Boots (@bootsUK)... Customer satisfaction survey E-mail:[[-Email-]] NO:[[random_digits(7)]]-[[random_digits(5)]]') driving recipients through a cloned Boots storefront landing page, a throwaway 'customer satisfaction survey' modal, a 'Secure Checkout' form harvesting full name, email, date of birth, phone number, and home address, and a final payment step harvesting payment-card data — all behind a bogus £0.00 order flow and a fake 'Skinny Tan' sponsor tie-in. Seven additional, unused subject-line/body-copy variants were found stored in the kit but never deployed in this run. A cosmetic PGP-signature block (styled HTML text mimicking BEGIN/END PGP SIGNED MESSAGE, Hash: SHA512, and BEGIN/END PGP SIGNATURE, with no actual cryptographic capability) was embedded purely to add visual legitimacy to the phishing page.

Huntress's MDR agent, deployed on the host on 2026-05-15 18:48 UTC (roughly 33 hours before the burst), raised its first critical detection at 2026-05-16 03:38:53 UTC as gm.exe began firing outbound SMTP connections. Over a roughly 104-second window (03:47:03–03:48:47 UTC) the mailer attempted connections to 1,641 distinct MX servers (Google, Microsoft, Yahoo, and regional providers) on TCP/25. The Huntress SOC mass-isolated all 25 endpoints on the customer network via a default-deny filter, flagged the compromised domain account for partner-side reset, severed the active RDP session, blocked further reconnection attempts from 212.93.152.37, and — per Windows Filtering Platform Event 5157 (logging the specific process path \device\harddiskvolume4\users\[user]\desktop\dam pe uk puterniiicccc\gm.exe) — blocked 29,954 additional outbound TCP/25 connection attempts post-isolation. Because delivery was direct-to-MX, the victim's own Microsoft 365/Google mail tenant was never used as a relay, limiting reputational blast radius to the victim's outbound IP rather than its mail domain; the true total of messages successfully sent before isolation cannot be quantified from the available logs, since WFP Event 5157 only captures connections blocked after isolation began. Huntress reported the compromised Bolivian government domain (ipelc.gob.bo, operated by the Instituto Plurinacional de Estudio de Lenguas y Culturas) and its /boots_store/ phishing kit to Centro de Gestión de Incidentes Informáticos (CGII), Bolivia's national CSIRT, coordinated through AGETIC, the country's state ICT agency.

The underlying root cause was a purely configuration-level exposure — an internet-facing RDWeb/RD Gateway portal with no MFA — rather than a software vulnerability, and Gammadyne Mailer itself is legitimate commercial software whose weaponization here is consistent with prior reported abuse of similar bulk-mailers (e.g., Gammadyne Mailer and Turbo-Mailer) by BEC- and phishing-focused actors, including the Nigeria-linked 'TMT' gang, for large-scale direct-to-MX email delivery from compromised infrastructure.

## MITRE ATT&CK

- T1583.003 Virtual Private Server
- T1584.001 Domains
- T1584.006 Web Services
- T1589.002 Email Addresses
- T1110.001 Password Guessing
- T1187 Forced Authentication
- T1078.002 Domain Accounts
- T1133 External Remote Services
- T1566.002 Spearphishing Link
- T1598.003 Spearphishing Link
- T1204.002 Malicious File
- T1021.001 Remote Desktop Protocol
- T1036 Masquerading
- T1005 Data from Local System
- T1570 Lateral Tool Transfer
- T1219 Remote Access Tools
- T1071.003 Mail Protocols
- T1114 Email Collection
- T1018 Remote System Discovery

## Sources

- [The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed](https://www.huntress.com/blog/terminal-server-phishing-stager-exposed)
- [Hackers Hijack Terminal Server to Launch 8.9 Million-Email Boots Phishing Campaign](https://www.itsecurityguru.org/2026/06/16/hackers-hijack-terminal-server-to-launch-8-9-million-email-boots-phishing-campaign/)
- [Fake Boots emails target millions in large phishing campaign](https://www.scworld.com/brief/fake-boots-emails-target-millions-in-large-phishing-campaign)
- [ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories](https://thehackernews.com/2026/06/threatsday-bulletin-claude-chat-abuse.html)
- [Eviction Strategies Tool — Countermeasure CM0042 (RDP hardening)](https://www.cisa.gov/eviction-strategies-tool/info-countermeasures/CM0042)
- [RD Web Access abuse: Fighting back](https://www.sophos.com/en-us/blog/rd-web-access-abuse-fighting-back)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1245
