The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed

June 15, 2026, 5:15 p.m.

Description

On May 15, 2026, Huntress agents detected an intrusion where threat actors compromised a terminal server to stage a massive phishing campaign rather than deploy ransomware. The attacker used legitimate bulk email software (Gammadyne Mailer) with a project file named 'dracii' (Romanian for 'the devils') and six recipient lists containing 8,894,920 email addresses. Operating from Romanian IP addresses, the actor impersonated UK pharmacy chain Boots through a fake customer satisfaction survey designed to harvest personal and payment card data. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which Huntress reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery to bypass mail relays, with the mailer configured to send from 666 threads simultaneously. Evidence suggests this Romanian operator has been running multiple UK-targeting campaigns since at least July 2025, rotating between retail, tax, and cryptocurrency themes.

Date

  • Created: June 15, 2026, 2:53 p.m.
  • Published: June 15, 2026, 2:53 p.m.
  • Modified: June 15, 2026, 5:15 p.m.

Indicators

  • 7fda5f10a2bc212daaa467484c56eb8abf3f3681f6405c5c2fac16d4124e44ca
  • 5d2ad1795b0dfc4a58424b2fa2f002246f653b119d362954ae270b6998e9d575
  • 6c428acbd91be85fedf9cbb334457ddea08ff624d4de88041749578e968d62a8
  • 375c2c84e2ca022c565507523b75c9c08a455479861ea41fc9b9ff74b3453445
  • c5ec55270af084d3c07d2918098d598bc2c5ca42f4189d69cdfcae2c958e5ec7
  • 13ac78f8f2ed76a03c85f0cdef07e5463aa64458303c0949090fcd81868ba8ca
  • 95fc58dc321b07ecc99d95359bcdee08a5beb519ead8e70e40f33928533a1b14
  • 80.94.95.37
  • 212.93.152.37
  • 216.152.151.168
  • 87.251.64.134
  • http://ipelc.gob.bo/boots_store/
  • https://ipelc.gob.bo/boots_store/

Additional Informations

  • Retail
  • Government
  • boots-rewards-uk.xyz
  • United Kingdom of Great Britain and Northern Ireland
  • Bolivia, Plurinational State of