→ Back to Home
Cloud Security

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

A significant cybersecurity incident has come to light involving a threat actor dubbed PCPJack, who has successfully hijacked more than 230 cloud servers hosted on major platforms including Amazon Web Services (AWS), Google Cloud, and Microsoft Azure. The objective of this extensive compromise is to establish a covert SMTP email relay network, enabling the anonymous dispatch of potentially malicious emails such as spam or phishing campaigns. According to threat intelligence firm Hunt.io, compromised business servers located across the United States, Europe, and Asia were systematically converted into SMTP proxies. These proxies were then rigorously verified for their mail relay capabilities and continuously synchronized with a downstream consumer every five minutes, ensuring a robust and distributed operational infrastructure. The discovery of this elaborate network was somewhat accidental, as PCPJack left two critical directories on a command-and-control (C2) server (specifically, "213.136.80[.]73") completely exposed and unprotected by any authentication. This oversight allowed Hunt.io to uncover a treasure trove of operational data, including the threat actor's source code, compiled binaries, deployment state logs, internet scanners, and various exploitation tools, alongside a live Sliver configuration. PCPJack's activities were first documented by SentinelOne in April 2026. At that time, SentinelOne identified a credential theft framework specifically designed to target cloud services. This earlier discovery also noted PCPJack's efforts to remove artifacts associated with TeamPCP, another prominent hacking group known for its software supply chain attacks, suggesting a potential rivalry or evolution in the threat landscape. The exposed toolkit included a Sliver-integrated SMTP proxy deployment toolkit, along with Chisel tunneling and proxy binaries compatible with various Linux CPU architectures. On victim systems, the binary was typically dropped as a hidden dot-prefixed file and persisted at "/var/tmp/.xs". Deployer scripts found in the directories were designed to load the Sliver C2 client configuration and filter for Linux beacons that had checked in recently. Each beacon was assigned a SOCKS5 proxy port derived deterministically from an MD5 hash of its Sliver UUID. The ultimate purpose of this 230-node network remains under investigation, but its design clearly supports large-scale email delivery operations.
#cloud security#smtp relay#pcpjack#cybercrime#threat actor#aws#google cloud#azure
Read original source