The threat actor PCPJack has compromised cloud servers on AWS, Google Cloud, and Microsoft Azure to establish a covert SMTP email relay network for large-scale malicious operations.
Key Points
- Researchers at Hunt.io discovered an unsecured command-and-control server containing source code, deployment logs, and Sliver-integrated SMTP proxy toolkits.
- The operation converts compromised Linux servers into SMTP proxies, persisting as hidden files at "/var/tmp/.xs" to relay emails.
- Beacons check in with the C2 server every five minutes, with the network filtering for hosts capable of connecting to Gmail's SMTP servers.
- The infrastructure maintains a pool of verified proxies, enriched with geolocation data, and syncs them to a downstream consumer server.
- The campaign currently utilizes at least 230 compromised nodes across the U.S., Europe, and Asia to facilitate its relay activities.