Skip to main content
Mallory
Back to intelligence
threat-infrastructure-trackingremote-access-implantcommand-and-control-methodpersistence-method

PCPJack Built a 230-Node Cloud SMTP Relay Network on Hijacked Servers

Updated 5d agoFirst seen Jun 5, 20263 sources

Researchers at Hunt.io uncovered a covert 230-node SMTP relay network built from compromised Linux servers hosted on AWS, Google Cloud, and Microsoft Azure after finding two unauthenticated open directories on 213.136.80[.]73. The exposed directories contained source code, binaries, deployment logs, scanners, exploitation tools, and a live Sliver configuration, revealing an active operation that used Sliver implants and Chisel tunneling to convert business servers across the U.S., Europe, and Asia into monitored SMTP-capable proxies. Deployment artifacts showed at least one completed wave in March 2026 with 230 successful uploads and executions, while verification data suggested earlier undocumented activity using different port ranges.

The recovered toolkit showed a structured workflow that established reverse SOCKS5 tunnels, persisted on Linux systems as /var/tmp/.xs or xsync, tested outbound access to smtp.gmail[.]com:587, assigned deterministic proxy ports, and synchronized verified relay nodes every five minutes via SCP to a downstream server at 38.242.204[.]245. Hunt.io said the infrastructure was likely intended for large-scale email delivery such as spam or phishing, although the final use remains unconfirmed. The campaign has been linked to PCPJack, a cloud-focused credential-theft framework previously identified by SentinelOne, but researchers said the relationship between PCPJack and TeamPCP infrastructure remains unclear and attribution is based primarily on shared infrastructure rather than definitive operator identification.

Share:
PCPJack Built a 230-Node Cloud SMTP Relay Network on Hijacked Servers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jun 5, 20265d ago

Hunt.io observed a 230-node PCPJack deployment wave in March 2026

State artifacts and deployment logs showed at least one completed March 2026 run in which PCPJack successfully uploaded and executed tooling on 230 Linux cloud servers to build SMTP-capable relay nodes.

PCPJack Exposed: Researchers Uncover 230-Node Cloud Email Relay Network

Hunt.io uncovered PCPJack's active cloud SMTP relay network

Analysis of the exposed files revealed an active covert SMTP relay network spanning compromised AWS, Google Cloud, and Microsoft Azure business servers across the U.S., Europe, and Asia, using Sliver implants and Chisel tunnels to maintain monitored proxy nodes.

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

Researchers found exposed PCPJack tooling on server 213.136.80[.]73

Hunt.io discovered two unauthenticated open directories on the internet-facing server 213.136.80[.]73 that exposed source code, binaries, deployment logs, scanners, exploitation tools, and a live Sliver-related working directory tied to the operation.

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

SentinelOne identified PCPJack during a cloud credential theft investigation

In April 2026, SentinelOne previously identified PCPJack as a cloud-focused credential theft framework and noted overlap or contention with TeamPCP-related infrastructure or artifacts.

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

28 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.