PCPJack is a cloud-focused threat actor and malware framework associated with opportunistic compromise of exposed internet-facing infrastructure and subsequent credential theft. The actor is known for targeting misconfigured or vulnerable cloud and developer-adjacent services, including exposed Docker, Kubernetes, Redis, MongoDB, and Ray environments, then harvesting cloud, GitHub, and npm credentials from compromised hosts. PCPJack has also been observed removing processes and artifacts associated with TeamPCP, indicating direct competition for access on victim systems and suggesting familiarity with TeamPCP tradecraft. PCPJack has been linked to campaigns affecting cloud servers hosted across Amazon Web Services, Google Cloud, and Microsoft Azure. In one documented operation, the actor converted compromised Linux servers into a covert SMTP relay network at scale, using open-source Sliver for command and control and Chisel for reverse tunneling and proxying. The tooling established persistence through cron or systemd mechanisms, assigned deterministic proxy ports to infected hosts, and continuously verified which nodes could relay outbound email traffic, indicating an operational objective centered on maintaining a reliable email proxy infrastructure. The ultimate downstream use of that relay network has not been conclusively established, though spam or phishing enablement is a plausible use case. The actor’s tactics, techniques, and procedures include internet-wide scanning for exposed services, exploitation of multiple known vulnerabilities for initial access, Linux post-compromise automation, credential harvesting, persistence, lateral propagation, and anti-competition behavior through removal of rival malware. PCPJack is widely described as a newer copycat or rival to TeamPCP rather than a fully independent tradecraft lineage, and some assessments suggest it may be operated by a former TeamPCP affiliate or someone with prior access to TeamPCP tooling. That relationship remains unconfirmed. No widely used aliases beyond PCPJack are established in the available reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newer credential- and secret-stealing worm that removes TeamPCP artifacts from compromised cloud infrastructure to displace a competing malware operator.
Rival activity cluster or worm operator targeting the same exposed cloud infrastructure as TeamPCP and removing TeamPCP tooling from compromised systems, possibly associated with a former TeamPCP operator.
Operated a 230-node cloud-based email relay network by compromising cloud servers and using them as monitored SMTP proxy infrastructure, likely for spam, phishing, or related email abuse.
Hijacked cloud and business servers to build a covert SMTP relay/proxy network, using compromised Linux hosts as email-capable proxies and syncing verified proxy lists to downstream infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.