Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cloud Servers Hijacked for Covert Email Relay Network

Cloud Servers Hijacked for Covert Email Relay Network

Posted on June 5, 2026 By CWS

Cloud Servers Hijacked for Covert Email Relay Network

The notorious threat actor known as PCPJack has commandeered 230 cloud servers across major platforms, including Amazon Web Services (AWS), Google Cloud, and Microsoft Azure, to establish a secretive SMTP email relay network. This alarming development has raised significant concerns within the cybersecurity community, highlighting vulnerabilities in cloud infrastructure.

Details of the SMTP Relay Setup

According to a statement from Hunt.io, the compromised servers, located throughout the U.S., Europe, and Asia, were covertly transformed into SMTP proxies. These proxies were then verified for their email relay capabilities and synchronized to a downstream consumer every five minutes. This infrastructure was operational at the time of discovery.

Investigations revealed source code, compiled binaries, and other critical artifacts left unsecured on a command-and-control (C2) server. This server lacked any authentication, providing valuable insights into the methods employed by PCPJack.

PCPJack’s Methodology and Tools

PCPJack first came to light in April 2026, identified by SentinelOne as a credential theft framework aimed at cloud services. The group’s tactics include terminating and removing traces of processes linked to TeamPCP, a known hacking entity involved in software supply chain attacks.

Among the discoveries were Sliver-integrated SMTP proxy deployment toolkits and Chisel tunneling binaries suited for various Linux CPU architectures. These binaries were hidden and persisted on compromised systems, while deployer scripts managed the configuration of the Sliver C2 client.

Operational Tactics and Implications

The operation’s scripts were designed to test SMTP capabilities, with those failing the criteria being disregarded. Successive script iterations removed such checks, emphasizing the operation’s focus on effective email relay.

The C2 server employed a Python script, “chisel_verifier.py,” to monitor active Chisel tunnel ports, testing each for SMTP functionality. Failed or inactive tunnels were pruned, ensuring the system’s efficiency. Verified proxies were documented with enriched IP data and regularly synced to a separate server.

Hunt.io describes the campaign as opportunistic, noting the 230 compromised nodes as observable outcomes. The ultimate purpose of this network, whether for spam, phishing, or other malicious activities, remains undetermined. However, the infrastructure’s scale suggests significant intent and capability.

The cybersecurity community continues to monitor the situation closely, aiming to mitigate any further threats posed by this sophisticated operation.

The Hacker News Tags:AWS, Azure, cloud security, Cyberattack, Cybersecurity, email relay, Google Cloud, PCPJack, SMTP relay, threat intelligence

Post navigation

Previous Post: HexStrike AI v6.0: Transforming Cybersecurity with BOAZ
Next Post: Cisco Reports 2026’s Seventh SD-WAN Zero-Day Flaw

Related Posts

UAC-0050 Expands to European Finance with RMS Malware UAC-0050 Expands to European Finance with RMS Malware The Hacker News
Optimizing SOC with AI and Human Expertise Optimizing SOC with AI and Human Expertise The Hacker News
Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale The Hacker News
How to Streamline Zero Trust Using the Shared Signals Framework How to Streamline Zero Trust Using the Shared Signals Framework The Hacker News
FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks The Hacker News
AI-Driven Exploitation Challenges Vulnerability Management AI-Driven Exploitation Challenges Vulnerability Management The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Craneware Confirms Cyberattack, Data Compromised
  • SecurityWeek Unveils Critical Impact Awards for Cybersecurity
  • Qilin Ransomware Exploits PAN-OS Vulnerability for Access
  • Microsoft to End Copilot Podcasts in 2026
  • Empirical Secures $25M for AI Cybersecurity Expansion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Craneware Confirms Cyberattack, Data Compromised
  • SecurityWeek Unveils Critical Impact Awards for Cybersecurity
  • Qilin Ransomware Exploits PAN-OS Vulnerability for Access
  • Microsoft to End Copilot Podcasts in 2026
  • Empirical Secures $25M for AI Cybersecurity Expansion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark