Summary
Key Points:
- PCPJack has hijacked 230 cloud servers across AWS, Google Cloud, and Azure to establish a covert SMTP relay network.
- The compromised servers, located in the U.S., Europe, and Asia, are utilized as SMTP proxies for potential spam or phishing campaigns, with the infrastructure still operational at the time of discovery.
- Immediate actions include monitoring for unusual SMTP activity and blocking outbound connections to suspicious IPs associated with the relay network.
Technical Details: The operation involves the use of a Sliver C2 client configuration and Chisel tunneling to facilitate communication. The C2 server was identified at "213.136.80[.]73," where open directories contained deployment scripts and binaries for Linux architectures.
MITRE ATT&CK Techniques:
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
- T1071.002 - Application Layer Protocol: File Transfer Protocol (Command and Control)
- T1203 - Exploit Public-Facing Application (Initial Access)
IOCs Mentioned:
- IPs: 213.136.80[.]73, 38.242.204[.]245
- Domains: smtp.gmail[.]com
This summary provides actionable intelligence for security analysts to mitigate risks associated with the ongoing PCPJack operations targeting cloud infrastructures.
Join the discussion — sign up to comment, upvote, and save articles.