AUTO-UPDATED

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

The threat actor PCPJack has compromised cloud servers on AWS, Google Cloud, and Microsoft Azure to establish a covert SMTP email relay network for large-scale malicious operations.

Key Points

  • Researchers at Hunt.io discovered an unsecured command-and-control server containing source code, deployment logs, and Sliver-integrated SMTP proxy toolkits.
  • The operation converts compromised Linux servers into SMTP proxies, persisting as hidden files at "/var/tmp/.xs" to relay emails.
  • Beacons check in with the C2 server every five minutes, with the network filtering for hosts capable of connecting to Gmail's SMTP servers.
  • The infrastructure maintains a pool of verified proxies, enriched with geolocation data, and syncs them to a downstream consumer server.
  • The campaign currently utilizes at least 230 compromised nodes across the U.S., Europe, and Asia to facilitate its relay activities.

Why it Matters

This campaign demonstrates how threat actors leverage major cloud infrastructure to build scalable, automated networks for spam or phishing delivery. The ability to maintain persistent, verified proxy lists poses a significant risk to email security and organizational reputation by facilitating high-volume malicious communications.
Internet Published by info@thehackernews.com (The Hacker News)
Read original