Summary
Key Points:
- PCPJack is a credential theft framework that targets exposed cloud infrastructure, specifically designed to evict artifacts associated with the TeamPCP threat actor group while harvesting credentials from various services.
- The impact includes significant data exposure and potential financial fraud, affecting systems like Docker, Kubernetes, MongoDB, and Redis. The toolset facilitates lateral movement and external propagation within victim environments.
- Recommended actions include implementing strict credential management practices, enforcing multi-factor authentication (MFA), and ensuring the use of IMDSv2 in AWS environments to prevent unauthorized access.
Technical Details: PCPJack exploits vulnerabilities such as CVE-2025-29927 (Next.js auth bypass) and CVE-2025-55182 (React deserialization) to propagate across networks. It utilizes Telegram for command and control (C2) communication.
MITRE ATT&CK Techniques:
- T1078 - Valid Accounts (Defense Evasion)
- T1190 - Exploit Public-Facing Application (Initial Access)
- T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)
- T1021.001 - Remote Services: Remote Desktop Protocol (Lateral Movement)
IOCs Mentioned:
- Domains: cdn[.]cloudfront-js[.]com, lastpass-login-help[.]com
- IP Addresses: 161.97.129[.]25, 161.97.135[.]154, 161.97.163[.]87, 161.97.186[.]175, 161.97.187[.]42, 193.187.129[.]143, 213.136.80[.]73, 38.242.204[.]245, 38.242.237[.]196, 38.242.245[.]147, 83.171.249[.]231
- File Hashes: SHA-1 hashes for various components including update.bin and bootstrap.sh
Join the discussion — sign up to comment, upvote, and save articles.