logo

PCPJack Exposed: Researchers Uncover 230-Node Cloud Email Relay Network

ID: 13351c12-82b4-5288-8585-0fc73d407aa4

STIX ID: report--13351c12-82b4-5288-8585-0fc73d407aa4

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Pierluigi Paganini

...
...

PCPJack compromised 230 cloud-hosted servers on AWS, Google Cloud, and Azure and instrumented them with Sliver implants and Chisel tunnels to create a monitored, self-healing SMTP relay network; researchers discovered the operation after the actor left deployment toolkits, logs, and C2 files in an open, unauthenticated directory, exposing the full deployment, persistence, verification, and proxy-enrichment workflows and suggesting large-scale email abuse (spam/phishing) as the likely objective.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.