The Devil, Eight Million Emails, and a Whole Lot of Milk
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A Huntress SOC investigation uncovered a Romanian threat actor who compromised a small client's internet-facing RDWeb terminal server via brute-forced credentials and no MFA. The attacker staged Gammadyne Mailer (a legitimate bulk email tool) with 8.9 million recipient addresses on the compromised desktop, configured to impersonate UK pharmacy chain Boots with a fake customer satisfaction survey. The phishing payload was hosted on a hijacked Bolivian government website (ipelc.gob.bo) to bypass reputation filters. Direct-to-MX delivery via 666 threads meant the victim's IP — not the attacker's — would be blocklisted. Huntress isolated all 25 endpoints mid-send, blocking 29,954 outbound SMTP connections in a 104-second burst. The investigation also revealed the attacker had been operating from at least July 2025, rotating the same Gammadyne project file across multiple compromised terminal servers targeting UK audiences with retail, tax, and crypto-themed lures.