Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cloud Servers Hijacked for Covert Email Relay Network

Cloud Servers Hijacked for Covert Email Relay Network

Posted on June 5, 2026 By CWS

Cloud Servers Hijacked for Covert Email Relay Network

The notorious threat actor known as PCPJack has commandeered 230 cloud servers across major platforms, including Amazon Web Services (AWS), Google Cloud, and Microsoft Azure, to establish a secretive SMTP email relay network. This alarming development has raised significant concerns within the cybersecurity community, highlighting vulnerabilities in cloud infrastructure.

Details of the SMTP Relay Setup

According to a statement from Hunt.io, the compromised servers, located throughout the U.S., Europe, and Asia, were covertly transformed into SMTP proxies. These proxies were then verified for their email relay capabilities and synchronized to a downstream consumer every five minutes. This infrastructure was operational at the time of discovery.

Investigations revealed source code, compiled binaries, and other critical artifacts left unsecured on a command-and-control (C2) server. This server lacked any authentication, providing valuable insights into the methods employed by PCPJack.

PCPJack’s Methodology and Tools

PCPJack first came to light in April 2026, identified by SentinelOne as a credential theft framework aimed at cloud services. The group’s tactics include terminating and removing traces of processes linked to TeamPCP, a known hacking entity involved in software supply chain attacks.

Among the discoveries were Sliver-integrated SMTP proxy deployment toolkits and Chisel tunneling binaries suited for various Linux CPU architectures. These binaries were hidden and persisted on compromised systems, while deployer scripts managed the configuration of the Sliver C2 client.

Operational Tactics and Implications

The operation’s scripts were designed to test SMTP capabilities, with those failing the criteria being disregarded. Successive script iterations removed such checks, emphasizing the operation’s focus on effective email relay.

The C2 server employed a Python script, “chisel_verifier.py,” to monitor active Chisel tunnel ports, testing each for SMTP functionality. Failed or inactive tunnels were pruned, ensuring the system’s efficiency. Verified proxies were documented with enriched IP data and regularly synced to a separate server.

Hunt.io describes the campaign as opportunistic, noting the 230 compromised nodes as observable outcomes. The ultimate purpose of this network, whether for spam, phishing, or other malicious activities, remains undetermined. However, the infrastructure’s scale suggests significant intent and capability.

The cybersecurity community continues to monitor the situation closely, aiming to mitigate any further threats posed by this sophisticated operation.

The Hacker News Tags:AWS, Azure, cloud security, Cyberattack, Cybersecurity, email relay, Google Cloud, PCPJack, SMTP relay, threat intelligence

Post navigation

Previous Post: HexStrike AI v6.0: Transforming Cybersecurity with BOAZ
Next Post: Cisco Reports 2026’s Seventh SD-WAN Zero-Day Flaw

Related Posts

GitHub Copilot Generates Harmful Code Despite Refusals GitHub Copilot Generates Harmful Code Despite Refusals The Hacker News
Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers The Hacker News
GitHub Vulnerability in Codespaces Exposes GITHUB_TOKEN GitHub Vulnerability in Codespaces Exposes GITHUB_TOKEN The Hacker News
Smart TV Proxyware and AI in Cybercrime: Key Updates Smart TV Proxyware and AI in Cybercrime: Key Updates The Hacker News
Avalon Malware Framework Unveils CrownX Ransomware Avalon Malware Framework Unveils CrownX Ransomware The Hacker News
The Impact of Robotic Process Automation (RPA) on Identity and Access Management The Impact of Robotic Process Automation (RPA) on Identity and Access Management The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark