logo

PCPJack Hijacked 230 AWS, GCP, and Azure Servers to Run a Hidden SMTP Relay Network

ID: 0721e1ec-8c74-5c6b-b172-86b341bc71f7

STIX ID: report--0721e1ec-8c74-5c6b-b172-86b341bc71f7

Feed Name: Hunt.io Blog

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

...
...

This report documents discovery of exposed operator directories for a PCPJack/XSync campaign: recovered Sliver-integrated deployers, stock Chisel binaries, and state files show iterative deployments culminating in a 230-node SOCKS5 proxy fleet used as SMTP relays; artifacts include credential-harvesting tools, persistence mechanisms, verification daemons, and multiple infrastructure pivots with actionable IOCs (IPs, file paths, process indicators).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.