The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
A threat actor compromised a terminal server to stage a large-scale phishing campaign targeting UK users by impersonating the Boots pharmacy chain. The attacker used legitimate bulk email software with nearly 8.9 million recipient addresses and hosted the phishing kit on a compromised Bolivian government website. The campaign employed direct-to-MX email delivery to bypass mail relays and was operated from Romanian IP addresses. This actor has conducted multiple UK-focused campaigns since mid-2025, using various themes such as retail, tax, and cryptocurrency to harvest personal and payment card data.
AI Analysis
Technical Summary
On May 15, 2026, Huntress agents identified an intrusion involving the compromise of a terminal server used to stage a massive phishing campaign rather than ransomware deployment. The attacker utilized Gammadyne Mailer with a project file named 'dracii' and six recipient lists totaling 8,894,920 email addresses. Operating from Romanian IPs, the actor impersonated the UK pharmacy chain Boots via a fake customer satisfaction survey designed to steal personal and payment card information. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which was reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery with 666 concurrent sending threads to bypass mail relays. Evidence indicates this Romanian operator has been conducting multiple UK-targeted campaigns since at least July 2025, rotating themes between retail, tax, and cryptocurrency.
Potential Impact
The campaign aims to steal personal and payment card data from recipients by impersonating a trusted UK pharmacy chain. The use of a compromised government website for hosting and direct-to-MX delivery techniques increases the likelihood of successful phishing email delivery and victim interaction. The large scale of nearly 9 million targeted email addresses indicates significant potential exposure and data theft risk for affected individuals.
Mitigation Recommendations
No official patch or fix applies as this is a phishing campaign leveraging compromised infrastructure and social engineering. Organizations should monitor for indicators of compromise such as the listed IP addresses, URLs, and domains. Users should be educated to recognize phishing attempts impersonating Boots or similar brands and avoid interacting with suspicious emails or links. The compromised Bolivian government website has been reported to the national CSIRT for remediation. Network defenses should consider blocking or scrutinizing traffic to the identified malicious infrastructure.
Indicators of Compromise
- ip: 87.251.64.134
- ip: 80.94.95.37
- ip: 216.152.151.168
- url: https://ipelc.gob.bo/boots_store/
- hash: 13ac78f8f2ed76a03c85f0cdef07e5463aa64458303c0949090fcd81868ba8ca
- hash: 375c2c84e2ca022c565507523b75c9c08a455479861ea41fc9b9ff74b3453445
- hash: 5d2ad1795b0dfc4a58424b2fa2f002246f653b119d362954ae270b6998e9d575
- hash: 6c428acbd91be85fedf9cbb334457ddea08ff624d4de88041749578e968d62a8
- hash: 7fda5f10a2bc212daaa467484c56eb8abf3f3681f6405c5c2fac16d4124e44ca
- hash: 95fc58dc321b07ecc99d95359bcdee08a5beb519ead8e70e40f33928533a1b14
- hash: c5ec55270af084d3c07d2918098d598bc2c5ca42f4189d69cdfcae2c958e5ec7
- ip: 212.93.152.37
- url: http://ipelc.gob.bo/boots_store/
- domain: boots-rewards-uk.xyz
The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
Description
A threat actor compromised a terminal server to stage a large-scale phishing campaign targeting UK users by impersonating the Boots pharmacy chain. The attacker used legitimate bulk email software with nearly 8.9 million recipient addresses and hosted the phishing kit on a compromised Bolivian government website. The campaign employed direct-to-MX email delivery to bypass mail relays and was operated from Romanian IP addresses. This actor has conducted multiple UK-focused campaigns since mid-2025, using various themes such as retail, tax, and cryptocurrency to harvest personal and payment card data.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On May 15, 2026, Huntress agents identified an intrusion involving the compromise of a terminal server used to stage a massive phishing campaign rather than ransomware deployment. The attacker utilized Gammadyne Mailer with a project file named 'dracii' and six recipient lists totaling 8,894,920 email addresses. Operating from Romanian IPs, the actor impersonated the UK pharmacy chain Boots via a fake customer satisfaction survey designed to steal personal and payment card information. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which was reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery with 666 concurrent sending threads to bypass mail relays. Evidence indicates this Romanian operator has been conducting multiple UK-targeted campaigns since at least July 2025, rotating themes between retail, tax, and cryptocurrency.
Potential Impact
The campaign aims to steal personal and payment card data from recipients by impersonating a trusted UK pharmacy chain. The use of a compromised government website for hosting and direct-to-MX delivery techniques increases the likelihood of successful phishing email delivery and victim interaction. The large scale of nearly 9 million targeted email addresses indicates significant potential exposure and data theft risk for affected individuals.
Mitigation Recommendations
No official patch or fix applies as this is a phishing campaign leveraging compromised infrastructure and social engineering. Organizations should monitor for indicators of compromise such as the listed IP addresses, URLs, and domains. Users should be educated to recognize phishing attempts impersonating Boots or similar brands and avoid interacting with suspicious emails or links. The compromised Bolivian government website has been reported to the national CSIRT for remediation. Network defenses should consider blocking or scrutinizing traffic to the identified malicious infrastructure.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.huntress.com/blog/terminal-server-phishing-stager-exposed"]
- Adversary
- null
- Pulse Id
- 6a3011d0c31292cdb59fd70b
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip87.251.64.134 | — | |
ip80.94.95.37 | — | |
ip216.152.151.168 | — | |
ip212.93.152.37 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://ipelc.gob.bo/boots_store/ | — | |
urlhttp://ipelc.gob.bo/boots_store/ | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash13ac78f8f2ed76a03c85f0cdef07e5463aa64458303c0949090fcd81868ba8ca | — | |
hash375c2c84e2ca022c565507523b75c9c08a455479861ea41fc9b9ff74b3453445 | — | |
hash5d2ad1795b0dfc4a58424b2fa2f002246f653b119d362954ae270b6998e9d575 | — | |
hash6c428acbd91be85fedf9cbb334457ddea08ff624d4de88041749578e968d62a8 | — | |
hash7fda5f10a2bc212daaa467484c56eb8abf3f3681f6405c5c2fac16d4124e44ca | — | |
hash95fc58dc321b07ecc99d95359bcdee08a5beb519ead8e70e40f33928533a1b14 | — | |
hashc5ec55270af084d3c07d2918098d598bc2c5ca42f4189d69cdfcae2c958e5ec7 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainboots-rewards-uk.xyz | — |
Threat ID: 6a3036a80b89be6888612aca
Added to database: 6/15/2026, 5:30:16 PM
Last enriched: 6/15/2026, 5:45:11 PM
Last updated: 6/15/2026, 6:39:27 PM
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.