The PCPJack threat actor has deployed a modular cloud worm across AWS, GCP, and Azure to orchestrate a 230-node covert SMTP relay network. The campaign utilizes a bootstrap shell script to exploit five high-severity vulnerabilities (including CVE-2026-1357 and CVE-2025-29927) targeting exposed Docker, Kubernetes, and RayML clusters. Once established, the malware deploys Sliver C2 for command-and-control and Chisel for SOCKS5 tunneling, effectively converting hijacked business servers into outbound mail proxies. Notably, PCPJack aggressively evicts existing "TeamPCP" infections to secure sole dominance and harvest credentials from AI service providers and cloud environments.
-
Propagation Mechanics: The Cloud Worm
- Employs an automated worm-like propagation strategy targeting exposed services including Redis, MongoDB, and RayML dashboard APIs (port 8265).
- Exploits five specific CVEs to gain initial access, facilitating rapid movement across multi-cloud environments.
- Utilizes a modular Python framework downloaded from AWS S3 buckets to perform credential parsing and cloud IP range lookups.
-
Infrastructure Orchestration: SMTP Relay Network
- Hijacked 230+ Linux servers globally to function as an outbound SMTP proxy network for masking phishing and spam campaigns.
- Implements a synchronization mechanism that updates a downstream consumer every five minutes to maintain relay availability.
- Repurposes compromised compute instances into persistent mail gateways, bypassing traditional organizational egress filters.
-
Technical Tooling: Sliver and Chisel
- Sliver C2: Uses the Sliver framework for primary remote execution, persistence, and command-and-control.
- Chisel: Deploys Chisel binaries (amd64, arm64, x86) to create secure tunnels for network pivoting and SMTP traffic proxying.
- C2 Exposure: Researchers discovered the full toolkit after the actor left an open directory on a Contabo-hosted C2 server (port 8444) without authentication.
-
Adversarial Dynamics: TeamPCP Eviction
- Actively scans for and deletes artifacts, processes, and tools associated with the rival "TeamPCP" threat actor.
- Performs aggressive credential harvesting during the eviction process to replace the previous occupant's access.
- Eschews traditional cryptocurrency mining in favor of high-value monetization via credential resale and fraud.
-
Targeted Assets: AI and Cloud Secrets
- Specifically targets credentials for AI providers (OpenAI, Anthropic) and developer tools (GitHub, Slack, HashiCorp Vault).
- Focuses on RayML worker environments, submitting malicious Python jobs to gain execution via unauthenticated APIs.
- Exfiltrates stolen tokens and SSH keys through encrypted Telegram channels and attacker-controlled infrastructure.
-
Defensive Actions: Detection and Mitigation
- Host Monitoring: Scan for a systemd service named
xsyncand unauthorized files located in/var/tmp/. - Network Filtering: Implement strict outbound firewall rules to block SMTP (port 25) traffic from all non-authorized mail gateways.
- Vulnerability Management: Prioritize patching of CVE-2026-1357 and securing exposed Kubernetes and RayML API endpoints.
- Host Monitoring: Scan for a systemd service named
Related posts
- Thehackernews
- Itnews
- The Hacker News — PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network
- Sentinelone
- Hunt
- techjacksolutions.com — PCPJack Credential Stealer Chains Five CVEs for Worm-Like Cloud Propagation and Broad Credential Harvest
- Labs
- Exchange
- Socdefenders
- Aiweekly
- Ctoatncsc
- Sentinelone
- Sentinelone
- feeds.feedburner.com — Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing