Threat Intelligence Analysis of a cloud-focused operation leveraging compromised AWS, Google Cloud, and Microsoft Azure servers to build a covert SMTP relay network.
Analyst
Rajkumar G
Date
June 2026
Classification
Public
Report ID
THI-2026-004
Executive Summary
This report examines PCPJack, a cloud-focused threat operation observed leveraging compromised cloud-hosted Linux servers to establish a covert SMTP relay infrastructure. The campaign demonstrates how attackers can convert legitimate business servers into proxy nodes capable of supporting large-scale email operations while blending into normal cloud traffic.
Key Intelligence Overview
Threat Actor
PCPJack
Category
Cloud Threat
Severity
High
Target
Cloud Servers
Primary Goal
SMTP Relay
Confidence
High
Threat Landscape
Cloud environments continue to attract threat actors due to scalability, availability, and the ability to hide malicious operations within legitimate infrastructure. SMTP relay abuse can support spam campaigns, phishing operations, malware distribution, and anonymous communication channels.
Targeted Platforms
Amazon Web Services (AWS)
Google Cloud Platform (GCP)
Microsoft Azure
Linux-Based Cloud Servers
Internet-Facing Business Infrastructure
Campaign Timeline
Initial Compromise
Cloud-hosted Linux servers are compromised.
Proxy Deployment
SOCKS5 proxy components are deployed.
SMTP Validation
Systems are tested for outbound mail relay capability.
Infrastructure Expansion
Verified hosts are added to the active relay network.
Continuous Synchronization
Active relay nodes are synchronized with downstream infrastructure.
Attack Chain Analysis
Initial Access
Attackers gain access to cloud-hosted Linux servers through compromised credentials, exposed services, or exploitation opportunities.
Execution
Custom binaries and tunneling tools are deployed to establish communication channels.
Persistence
System services and scheduled tasks are leveraged to maintain long-term access.
Command and Control
Compromised hosts maintain communication with attacker-controlled infrastructure.
Proxy Operations
Compromised systems function as SMTP-capable proxy nodes capable of forwarding traffic.
Observed Tooling
Sliver C2 Framework
Chisel Tunneling Utility
Linux Persistence Mechanisms
SMTP Validation Scripts
Cloud Infrastructure Automation
MITRE ATT&CK Mapping
Tactic
Technique
ID
Execution
Command and Scripting Interpreter
T1059
Persistence
Create or Modify System Process
T1543
Command and Control
Proxy
T1090
Command and Control
Application Layer Protocol
T1071
Discovery
System Information Discovery
T1082
Indicators of Interest
Unexpected SOCKS5 proxy services
Hidden binaries within temporary directories
Unusual outbound SMTP traffic
Persistence through cron jobs or systemd services
Connections to unknown command-and-control infrastructure
Detection Opportunities
Monitor outbound SMTP traffic from cloud servers.
Review creation of unauthorized services.
Inspect hidden files within temporary directories.
Monitor proxy-related processes.
Analyze unusual cloud workload behavior.
Review persistence mechanisms regularly.
Defensive Recommendations
Implement cloud workload monitoring.
Restrict unnecessary outbound SMTP traffic.
Audit Linux persistence mechanisms.
Enforce strong credential management.
Enable multi-factor authentication.
Monitor cloud administrative activity.
Deploy endpoint detection and response solutions.
SOC Analyst Assessment
This campaign demonstrates how cloud infrastructure can be weaponized to support large-scale malicious operations. Security teams should prioritize cloud visibility, outbound traffic monitoring, credential protection, and detection of unauthorized proxy services.