PCPJack Exposed: Researchers Uncover 230-Node Cloud Email Relay Network
ID: 13351c12-82b4-5288-8585-0fc73d407aa4
STIX ID: report--13351c12-82b4-5288-8585-0fc73d407aa4
Feed Name: Security Affairs
PCPJack compromised 230 cloud-hosted servers on AWS, Google Cloud, and Azure and instrumented them with Sliver implants and Chisel tunnels to create a monitored, self-healing SMTP relay network; researchers discovered the operation after the actor left deployment toolkits, logs, and C2 files in an open, unauthenticated directory, exposing the full deployment, persistence, verification, and proxy-enrichment workflows and suggesting large-scale email abuse (spam/phishing) as the likely objective.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
