Attackers breached a public RDWeb/RD Gateway terminal server using a valid domain credential that lacked MFA, then used the host to stage a large phishing operation. Huntress found the intrusion shortly after onboarding a 25-endpoint customer and linked the primary access to Romanian-source IPs 80.94.95[.]37 and 212.93.152[.]37, which authenticated to the exposed portal, downloaded the published .rdp file, and reconnected to an existing RDP session. A separate US-based brute-force source, 216.152.151[.]168, also guessed the same weak password but did not appear to use the access.
On the server, the actor deployed Gammadyne Mailer (gm.exe) with a long-lived project file and six recipient lists containing 8,894,920 addresses, then launched a Boots-themed phishing campaign offering a fake free-gift survey. The emails directed victims to hxxps://ipelc.gob[.]bo/boots_store/, a phishing kit hosted on a compromised Bolivian government domain, and were delivered directly to recipient mail servers over SMTP rather than through the victim organization's mail tenant. After the host was isolated, it generated 29,954 blocked outbound SMTP connection attempts to 1,641 recipient mail servers in 104 seconds; Huntress isolated all endpoints, advised a password reset for the compromised account, and notified Bolivia's national CSIRT about the abused government site.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
After identifying the abuse, Huntress mass-isolated all 25 endpoints and alerted the partner to reset the compromised account. Huntress also notified Bolivia's national CSIRT, CGII/AGETIC, that the government site hosting the phishing kit had been compromised.
On the compromised server, the actor deployed and ran Gammadyne Mailer with a long-lived project file and six recipient lists totaling 8,894,920 addresses. The campaign impersonated Boots UK and sent victims to a phishing kit hosted at ipelc.gob.bo on a compromised Bolivian government domain.
Before Huntress onboarding, attackers accessed a public RDWeb/RD Gateway terminal server using a valid domain credential on an account that did not have MFA enabled. Huntress tied the intrusion primarily to Romanian-source IPs that logged into the exposed RDWeb portal and reconnected to an existing RDP session.
Huntress investigated an intrusion discovered within hours of onboarding a 25-endpoint customer. The investigation found the terminal server had already been compromised and was being used for direct-to-MX phishing delivery over TCP port 25.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.