PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network
ID: 62a61ba5-1c79-561e-a037-7fa9268e4a46
STIX ID: report--62a61ba5-1c79-561e-a037-7fa9268e4a46
Feed Name: The Hacker News
Hunt.io discovered that PCPJack compromised cloud servers across AWS, Google Cloud, and Azure and converted them into a 230-node covert SMTP relay/proxy network; exposed files on a C2 server revealed Sliver- and Chisel-based tooling, deployer and verifier scripts, persistence artifacts, and a pipeline that tests and syncs verified proxies every five minutes to a downstream consumer, indicating active exploitation and large-scale email-delivery capability for spam, phishing, or other abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
