PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network
In order to establish a secret SMTP email relay network, the threat actor known as PCPJack has taken control of cloud servers connected to Google Cloud, Microsoft Azure, and Amazon Web Services (AWS).
According to a statement from Hunt.io, compromised company servers in the US, Europe, and Asia were discreetly transformed into SMTP proxies, checked for mail relay functionality, and synchronized to a downstream customer every five minutes. When we discovered it, the infrastructure was still operational.
After the threat actor responsible for the operation left two open directories on a command-and-control (C2) server ("213.136.80[.]73") without any authentication, the threat intelligence firm claimed to have discovered source code, compiled binaries, deployment state logs, internet s...

