The Devil, Eight Million Emails, and a Whole Lot of Milk

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A Huntress SOC investigation uncovered a Romanian threat actor who compromised a small client's internet-facing RDWeb terminal server via brute-forced credentials and no MFA. The attacker staged Gammadyne Mailer (a legitimate bulk email tool) with 8.9 million recipient addresses on the compromised desktop, configured to impersonate UK pharmacy chain Boots with a fake customer satisfaction survey. The phishing payload was hosted on a hijacked Bolivian government website (ipelc.gob.bo) to bypass reputation filters. Direct-to-MX delivery via 666 threads meant the victim's IP — not the attacker's — would be blocklisted. Huntress isolated all 25 endpoints mid-send, blocking 29,954 outbound SMTP connections in a 104-second burst. The investigation also revealed the attacker had been operating from at least July 2025, rotating the same Gammadyne project file across multiple compromised terminal servers targeting UK audiences with retail, tax, and crypto-themed lures.

28m read timeFrom huntress.com
Post cover image
Table of contents
BackgroundA logon we already had a name forFour keys to the same lockThe devil's workshopA whole lot of milkBoots, a free gift, and a survey you should not takeThe payload lived on a Bolivian government websiteDirect to the world's mail serversSo what did Huntress do?ConclusionIndicators of Compromise (IoCs)
191 Impressions