Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A threat actor designated PCPJack has built a 230-node covert email relay network by compromising cloud servers across AWS, Google Cloud, and Microsoft Azure, likely through exposed or stolen credentials. Researchers at Hunt.io discovered the actor’s operational files, including source code and a Sliver C2 framework configuration, exposed in open, unauthenticated directories while the campaign was still running. The relay network synchronizes with downstream consumers every five minutes. Any organization running cloud compute instances with weak credential hygiene or internet-exposed management interfaces faces direct risk of infrastructure compromise and abuse for large-scale malicious email operations.

Author

Tech Jacks Solutions