FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

PCPJack SMTP Relay Network on AWS, GCP, and Azure

The PCPJack threat actor has deployed a modular cloud worm across AWS, GCP, and Azure to orchestrate a 230-node covert SMTP relay network. The campaign utilizes a bootstrap shell script to exploit five high-severity vulnerabilities (including CVE-2026-1357 and CVE-2025-29927) targeting exposed Docker, Kubernetes, and RayML clusters. Once established, the malware deploys Sliver C2 for command-and-control and Chisel for SOCKS5 tunneling, effectively converting hijacked business servers into outbound mail proxies. Notably, PCPJack aggressively evicts existing "TeamPCP" infections to secure sole dominance and harvest credentials from AI service providers and cloud environments.


LINK COPIED TO CLIPBOARD