The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
On May 15, 2026, Huntress agents detected an intrusion where threat actors compromised a terminal server to stage a massive phishing campaign rather than deploy ransomware. The attacker used legitimate bulk email software (Gammadyne Mailer) with a project file named 'dracii' (Romanian for 'the devils') and six recipient lists containing 8,894,920 email addresses. Operating from Romanian IP addresses, the actor impersonated UK pharmacy chain Boots through a fake customer satisfaction survey designed to harvest personal and payment card data. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which Huntress reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery to bypass mail relays, with the mailer configured to send from 666 threads simultaneously. Evidence suggests this Romanian operator has been running multiple UK-targeting campaigns since at least July 2025, rotating between retail, tax, and cryptocurrency themes.
AI Analysis
Technical Summary
On May 15, 2026, Huntress agents identified an intrusion involving the compromise of a terminal server used to stage a massive phishing campaign rather than ransomware deployment. The attacker utilized Gammadyne Mailer with a project file named 'dracii' and six recipient lists totaling 8,894,920 email addresses. Operating from Romanian IPs, the actor impersonated the UK pharmacy chain Boots via a fake customer satisfaction survey designed to steal personal and payment card information. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which was reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery with 666 concurrent sending threads to bypass mail relays. Evidence indicates this Romanian operator has been conducting multiple UK-targeted campaigns since at least July 2025, rotating themes between retail, tax, and cryptocurrency.
Potential Impact
The campaign aims to steal personal and payment card data from recipients by impersonating a trusted UK pharmacy chain. The use of a compromised government website for hosting and direct-to-MX delivery techniques increases the likelihood of successful phishing email delivery and victim interaction. The large scale of nearly 9 million targeted email addresses indicates significant potential exposure and data theft risk for affected individuals.
Mitigation Recommendations
No official patch or fix applies as this is a phishing campaign leveraging compromised infrastructure and social engineering. Organizations should monitor for indicators of compromise such as the listed IP addresses, URLs, and domains. Users should be educated to recognize phishing attempts impersonating Boots or similar brands and avoid interacting with suspicious emails or links. The compromised Bolivian government website has been reported to the national CSIRT for remediation. Network defenses should consider blocking or scrutinizing traffic to the identified malicious infrastructure.
Indicators of Compromise
- ip: 87.251.64.134
- ip: 80.94.95.37
- ip: 216.152.151.168
- url: https://ipelc.gob.bo/boots_store/
- hash: 13ac78f8f2ed76a03c85f0cdef07e5463aa64458303c0949090fcd81868ba8ca
- hash: 375c2c84e2ca022c565507523b75c9c08a455479861ea41fc9b9ff74b3453445
- hash: 5d2ad1795b0dfc4a58424b2fa2f002246f653b119d362954ae270b6998e9d575
- hash: 6c428acbd91be85fedf9cbb334457ddea08ff624d4de88041749578e968d62a8
- hash: 7fda5f10a2bc212daaa467484c56eb8abf3f3681f6405c5c2fac16d4124e44ca
- hash: 95fc58dc321b07ecc99d95359bcdee08a5beb519ead8e70e40f33928533a1b14
- hash: c5ec55270af084d3c07d2918098d598bc2c5ca42f4189d69cdfcae2c958e5ec7
- ip: 212.93.152.37
- url: http://ipelc.gob.bo/boots_store/
- domain: boots-rewards-uk.xyz
The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
Description
On May 15, 2026, Huntress agents detected an intrusion where threat actors compromised a terminal server to stage a massive phishing campaign rather than deploy ransomware. The attacker used legitimate bulk email software (Gammadyne Mailer) with a project file named 'dracii' (Romanian for 'the devils') and six recipient lists containing 8,894,920 email addresses. Operating from Romanian IP addresses, the actor impersonated UK pharmacy chain Boots through a fake customer satisfaction survey designed to harvest personal and payment card data. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which Huntress reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery to bypass mail relays, with the mailer configured to send from 666 threads simultaneously. Evidence suggests this Romanian operator has been running multiple UK-targeting campaigns since at least July 2025, rotating between retail, tax, and cryptocurrency themes.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On May 15, 2026, Huntress agents identified an intrusion involving the compromise of a terminal server used to stage a massive phishing campaign rather than ransomware deployment. The attacker utilized Gammadyne Mailer with a project file named 'dracii' and six recipient lists totaling 8,894,920 email addresses. Operating from Romanian IPs, the actor impersonated the UK pharmacy chain Boots via a fake customer satisfaction survey designed to steal personal and payment card information. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which was reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery with 666 concurrent sending threads to bypass mail relays. Evidence indicates this Romanian operator has been conducting multiple UK-targeted campaigns since at least July 2025, rotating themes between retail, tax, and cryptocurrency.
Potential Impact
The campaign aims to steal personal and payment card data from recipients by impersonating a trusted UK pharmacy chain. The use of a compromised government website for hosting and direct-to-MX delivery techniques increases the likelihood of successful phishing email delivery and victim interaction. The large scale of nearly 9 million targeted email addresses indicates significant potential exposure and data theft risk for affected individuals.
Mitigation Recommendations
No official patch or fix applies as this is a phishing campaign leveraging compromised infrastructure and social engineering. Organizations should monitor for indicators of compromise such as the listed IP addresses, URLs, and domains. Users should be educated to recognize phishing attempts impersonating Boots or similar brands and avoid interacting with suspicious emails or links. The compromised Bolivian government website has been reported to the national CSIRT for remediation. Network defenses should consider blocking or scrutinizing traffic to the identified malicious infrastructure.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.huntress.com/blog/terminal-server-phishing-stager-exposed"]
- Adversary
- null
- Pulse Id
- 6a3011d0c31292cdb59fd70b
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip87.251.64.134 | — | |
ip80.94.95.37 | — | |
ip216.152.151.168 | — | |
ip212.93.152.37 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://ipelc.gob.bo/boots_store/ | — | |
urlhttp://ipelc.gob.bo/boots_store/ | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash13ac78f8f2ed76a03c85f0cdef07e5463aa64458303c0949090fcd81868ba8ca | — | |
hash375c2c84e2ca022c565507523b75c9c08a455479861ea41fc9b9ff74b3453445 | — | |
hash5d2ad1795b0dfc4a58424b2fa2f002246f653b119d362954ae270b6998e9d575 | — | |
hash6c428acbd91be85fedf9cbb334457ddea08ff624d4de88041749578e968d62a8 | — | |
hash7fda5f10a2bc212daaa467484c56eb8abf3f3681f6405c5c2fac16d4124e44ca | — | |
hash95fc58dc321b07ecc99d95359bcdee08a5beb519ead8e70e40f33928533a1b14 | — | |
hashc5ec55270af084d3c07d2918098d598bc2c5ca42f4189d69cdfcae2c958e5ec7 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainboots-rewards-uk.xyz | — |
Threat ID: 6a3036a80b89be6888612aca
Added to database: 06/15/2026, 17:30:16 UTC
Last enriched: 06/15/2026, 17:45:11 UTC
Last updated: 07/29/2026, 21:35:38 UTC
Views: 240
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.