Site icon VMVirtualMachine.com

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

Ravie LakshmananJun 05, 2026Threat Intelligence / Cloud Security

The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SMTP email relay network.

“Compromised business servers across the U.S., Europe, and Asia were quietly converted into SMTP proxies, verified for mail relay capability, and synced to a downstream consumer every five minutes,” Hunt.io said in a statement. “The infrastructure was still running when we found it.”

The threat intelligence company said it found source code, compiled binaries, deployment state logs, internet scanners, exploitation tooling, and a live Sliver configuration after the threat actor behind the operation left two open directories on a command-and-control (C2) server (“213.136.80[.]73”) without any authentication.

PCPJack was first discovered by SentinelOne in April 2026 after it identified a credential theft framework that specifically…

https://thehackernews.com/2026/06/pcpjack-hijacks-230-aws-google-cloud.html

Exit mobile version