Tag: azure

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network
News

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

In order to establish a secret SMTP email relay network, the threat actor known as PCPJack has taken control of cloud servers connected to Google Cloud, Microsoft Azure, and Amazon Web Services (AWS). According to a statement from Hunt.io, compromised company servers in the US, Europe, and Asia were discreetly transformed into SMTP proxies, checked for mail relay functionality, and synchronized to a downstream customer every five minutes. When we discovered it, the infrastructure was still operational. After the threat actor responsible for the operation left two open directories on a command-and-control (C2) server ("213.136.80[.]73") without any authentication, the threat intelligence firm claimed to have discovered source code, compiled binaries, deployment state logs, internet s...