The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
June 15, 2026, 5:15 p.m.
Description
On May 15, 2026, Huntress agents detected an intrusion where threat actors compromised a terminal server to stage a massive phishing campaign rather than deploy ransomware. The attacker used legitimate bulk email software (Gammadyne Mailer) with a project file named 'dracii' (Romanian for 'the devils') and six recipient lists containing 8,894,920 email addresses. Operating from Romanian IP addresses, the actor impersonated UK pharmacy chain Boots through a fake customer satisfaction survey designed to harvest personal and payment card data. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which Huntress reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery to bypass mail relays, with the mailer configured to send from 666 threads simultaneously. Evidence suggests this Romanian operator has been running multiple UK-targeting campaigns since at least July 2025, rotating between retail, tax, and cryptocurrency themes.
Tags
Date
- Created: June 15, 2026, 2:53 p.m.
- Published: June 15, 2026, 2:53 p.m.
- Modified: June 15, 2026, 5:15 p.m.
Indicators
- 7fda5f10a2bc212daaa467484c56eb8abf3f3681f6405c5c2fac16d4124e44ca
- 5d2ad1795b0dfc4a58424b2fa2f002246f653b119d362954ae270b6998e9d575
- 6c428acbd91be85fedf9cbb334457ddea08ff624d4de88041749578e968d62a8
- 375c2c84e2ca022c565507523b75c9c08a455479861ea41fc9b9ff74b3453445
- c5ec55270af084d3c07d2918098d598bc2c5ca42f4189d69cdfcae2c958e5ec7
- 13ac78f8f2ed76a03c85f0cdef07e5463aa64458303c0949090fcd81868ba8ca
- 95fc58dc321b07ecc99d95359bcdee08a5beb519ead8e70e40f33928533a1b14
- 80.94.95.37
- 212.93.152.37
- 216.152.151.168
- 87.251.64.134
- http://ipelc.gob.bo/boots_store/
- https://ipelc.gob.bo/boots_store/
Additional Informations
- Retail
- Government
- boots-rewards-uk.xyz
- United Kingdom of Great Britain and Northern Ireland
- Bolivia, Plurinational State of