THREAT INTELLIGENCE REPORT

PCPJack Cloud SMTP Relay Infrastructure Campaign

Threat Intelligence Analysis of a cloud-focused operation leveraging compromised AWS, Google Cloud, and Microsoft Azure servers to build a covert SMTP relay network.

Analyst
Rajkumar G
Date
June 2026
Classification
Public
Report ID
THI-2026-004

Executive Summary

This report examines PCPJack, a cloud-focused threat operation observed leveraging compromised cloud-hosted Linux servers to establish a covert SMTP relay infrastructure. The campaign demonstrates how attackers can convert legitimate business servers into proxy nodes capable of supporting large-scale email operations while blending into normal cloud traffic.

Key Intelligence Overview

Threat Actor

PCPJack

Category

Cloud Threat

Severity

High

Target

Cloud Servers

Primary Goal

SMTP Relay

Confidence

High

Threat Landscape

Cloud environments continue to attract threat actors due to scalability, availability, and the ability to hide malicious operations within legitimate infrastructure. SMTP relay abuse can support spam campaigns, phishing operations, malware distribution, and anonymous communication channels.

Targeted Platforms

Campaign Timeline

Initial Compromise

Cloud-hosted Linux servers are compromised.

Proxy Deployment

SOCKS5 proxy components are deployed.

SMTP Validation

Systems are tested for outbound mail relay capability.

Infrastructure Expansion

Verified hosts are added to the active relay network.

Continuous Synchronization

Active relay nodes are synchronized with downstream infrastructure.

Attack Chain Analysis

Initial Access

Attackers gain access to cloud-hosted Linux servers through compromised credentials, exposed services, or exploitation opportunities.

Execution

Custom binaries and tunneling tools are deployed to establish communication channels.

Persistence

System services and scheduled tasks are leveraged to maintain long-term access.

Command and Control

Compromised hosts maintain communication with attacker-controlled infrastructure.

Proxy Operations

Compromised systems function as SMTP-capable proxy nodes capable of forwarding traffic.

Observed Tooling

MITRE ATT&CK Mapping

Tactic Technique ID
Execution Command and Scripting Interpreter T1059
Persistence Create or Modify System Process T1543
Command and Control Proxy T1090
Command and Control Application Layer Protocol T1071
Discovery System Information Discovery T1082

Indicators of Interest

Detection Opportunities

Defensive Recommendations

  1. Implement cloud workload monitoring.
  2. Restrict unnecessary outbound SMTP traffic.
  3. Audit Linux persistence mechanisms.
  4. Enforce strong credential management.
  5. Enable multi-factor authentication.
  6. Monitor cloud administrative activity.
  7. Deploy endpoint detection and response solutions.

SOC Analyst Assessment

This campaign demonstrates how cloud infrastructure can be weaponized to support large-scale malicious operations. Security teams should prioritize cloud visibility, outbound traffic monitoring, credential protection, and detection of unauthorized proxy services.

Skills Demonstrated

References