Suspicious Gammadyne Mailer Execution for Direct-to-MX Spam

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-01
Updated
2026-10-01

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects execution of the Gammadyne Mailer utility, matching the direct-to-MX spam blast run from a compromised terminal server in a phishing stager intrusion. Adversaries use this bulk mailer to send high volumes of outbound SMTP directly to recipient mail exchangers, bypassing corporate mail gateways. Its presence on a server is a strong indicator of abuse for mass phishing.

Related detections9 linkedT1566 — drag to rearrange
Suspicious OAuth Sign-In Using Visual Studio Code Client and Auth Broker
Suspicious AWS AiTM Phishing Kit Endpoint Access via Proxy
Malicious Office 365 Email Rule Breach - On Behalf (via office365)
Suspicious AWS Console AiTM Phishing Kit API Endpoints
Suspicious PowerShell Download of updserc Archive to AppData via ClickFix
AWS CloudTrail SSM SendCommand Successful Execution for Instance
Proxy WebDAV MiniRedir Drives Execution from External Shares
Windows WebDAV Temporary File Creation with Suspicious Extensions
Okta FastPass blocks phishing authentication attempts via MFA
Suspicious Gammadyne Mailer Execution for Direct-to-MX Spam
Pivot detection · T1566 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.