logo

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

ID: 62a61ba5-1c79-561e-a037-7fa9268e4a46

STIX ID: report--62a61ba5-1c79-561e-a037-7fa9268e4a46

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: [email protected] (The Hacker News)

...
...

Hunt.io discovered that PCPJack compromised cloud servers across AWS, Google Cloud, and Azure and converted them into a 230-node covert SMTP relay/proxy network; exposed files on a C2 server revealed Sliver- and Chisel-based tooling, deployer and verifier scripts, persistence artifacts, and a pipeline that tests and syncs verified proxies every five minutes to a downstream consumer, indicating active exploitation and large-scale email-delivery capability for spam, phishing, or other abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.