Back to all lessons
Awareness Lessons
4 months ago

PCPJack Compromises 230 Cloud Servers for Covert SMTP Relay Network

PCPJack successfully compromised 230 cloud servers across major cloud providers by exploiting weak access controls and poor security monitoring. The attackers deployed Sliver malware and created a sophisticated SMTP relay network that operated undetected, converting legitimate business servers into email proxies. The breach was only discovered when Hunt.io found exposed C2 directories, highlighting the critical importance of proper access management and continuous monitoring in cloud environments. This incident demonstrates how compromised cloud infrastructure can be weaponized for large-scale malicious operations while remaining hidden from defenders.

Tactical Insight

Immediate actions

  • Audit all cloud server access controls and remove unnecessary permissions immediately
  • Deploy endpoint detection and response (EDR) solutions on all cloud instances
  • Scan for indicators of compromise including Sliver malware signatures

Long-term improvements

  • Implement multi-factor authentication for all cloud server access
  • Establish continuous security monitoring with automated alerting for suspicious activities
  • Deploy cloud security posture management (CSPM) tools to detect misconfigurations

Detection measures

  • Monitor outbound SMTP traffic patterns for unusual relay behavior
  • Set up alerts for unauthorized software installations and C2 communication attempts
  • Implement regular vulnerability assessments of all cloud infrastructure