Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed

0
Medium
Published: Mon Jun 15 2026 (06/15/2026, 14:53:04 UTC)
Source: AlienVault OTX General

Description

A threat actor compromised a terminal server to stage a large-scale phishing campaign targeting UK users by impersonating the Boots pharmacy chain. The attacker used legitimate bulk email software with nearly 8.9 million recipient addresses and hosted the phishing kit on a compromised Bolivian government website. The campaign employed direct-to-MX email delivery to bypass mail relays and was operated from Romanian IP addresses. This actor has conducted multiple UK-focused campaigns since mid-2025, using various themes such as retail, tax, and cryptocurrency to harvest personal and payment card data.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/15/2026, 17:45:11 UTC

Technical Analysis

On May 15, 2026, Huntress agents identified an intrusion involving the compromise of a terminal server used to stage a massive phishing campaign rather than ransomware deployment. The attacker utilized Gammadyne Mailer with a project file named 'dracii' and six recipient lists totaling 8,894,920 email addresses. Operating from Romanian IPs, the actor impersonated the UK pharmacy chain Boots via a fake customer satisfaction survey designed to steal personal and payment card information. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which was reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery with 666 concurrent sending threads to bypass mail relays. Evidence indicates this Romanian operator has been conducting multiple UK-targeted campaigns since at least July 2025, rotating themes between retail, tax, and cryptocurrency.

Potential Impact

The campaign aims to steal personal and payment card data from recipients by impersonating a trusted UK pharmacy chain. The use of a compromised government website for hosting and direct-to-MX delivery techniques increases the likelihood of successful phishing email delivery and victim interaction. The large scale of nearly 9 million targeted email addresses indicates significant potential exposure and data theft risk for affected individuals.

Mitigation Recommendations

No official patch or fix applies as this is a phishing campaign leveraging compromised infrastructure and social engineering. Organizations should monitor for indicators of compromise such as the listed IP addresses, URLs, and domains. Users should be educated to recognize phishing attempts impersonating Boots or similar brands and avoid interacting with suspicious emails or links. The compromised Bolivian government website has been reported to the national CSIRT for remediation. Network defenses should consider blocking or scrutinizing traffic to the identified malicious infrastructure.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.huntress.com/blog/terminal-server-phishing-stager-exposed"]
Adversary
null
Pulse Id
6a3011d0c31292cdb59fd70b
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip87.251.64.134
ip80.94.95.37
ip216.152.151.168
ip212.93.152.37

Url

ValueDescriptionCopy
urlhttps://ipelc.gob.bo/boots_store/
urlhttp://ipelc.gob.bo/boots_store/

Hash

ValueDescriptionCopy
hash13ac78f8f2ed76a03c85f0cdef07e5463aa64458303c0949090fcd81868ba8ca
hash375c2c84e2ca022c565507523b75c9c08a455479861ea41fc9b9ff74b3453445
hash5d2ad1795b0dfc4a58424b2fa2f002246f653b119d362954ae270b6998e9d575
hash6c428acbd91be85fedf9cbb334457ddea08ff624d4de88041749578e968d62a8
hash7fda5f10a2bc212daaa467484c56eb8abf3f3681f6405c5c2fac16d4124e44ca
hash95fc58dc321b07ecc99d95359bcdee08a5beb519ead8e70e40f33928533a1b14
hashc5ec55270af084d3c07d2918098d598bc2c5ca42f4189d69cdfcae2c958e5ec7

Domain

ValueDescriptionCopy
domainboots-rewards-uk.xyz

Threat ID: 6a3036a80b89be6888612aca

Added to database: 6/15/2026, 5:30:16 PM

Last enriched: 6/15/2026, 5:45:11 PM

Last updated: 6/15/2026, 6:39:27 PM

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses