news.mlab.sh
Back to the feed
threat-intel

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

High
Summary

PCPJack, a threat actor initially linked to TeamPCP, has established a covert SMTP email relay network by hijacking 230 cloud servers across AWS, Google Cloud, and Azure. The operation involved converting business servers into SMTP proxies and syncing them to a downstream server every five minutes, utilizing tools like Sliver and Chisel. The activity was discovered by Hunt.io and SentinelOne, highlighting the opportunistic nature of the campaign and the potential for malicious use of the infrastructure.

The discovery of PCPJack’s operation began when Hunt.io identified a network of compromised cloud servers being utilized as SMTP relay proxies. These servers, hosted on AWS, Google Cloud, and Azure, were quietly converted and synced to a downstream server every five minutes, creating a covert network for email relay. The threat actor deployed tools like Sliver and Chisel, along with SMTP quality gates, to ensure the proxies were functional and suitable for relaying email. The operation was characterized by opportunistic behavior, with the exact motives remaining unclear at the time of discovery.

The investigation revealed a sophisticated setup, including deployer scripts that managed the Sliver C2 client configuration and beacons – implants that periodically checked in with the C2 server. These beacons utilized a unique SOCKS5 proxy port derived from an MD5 hash of their Sliver UUID, eliminating the need for a shared port registry. Furthermore, the attacker employed diagnostic scripts to monitor the health of the proxies and remove failed tunnels. The C2 server ran a Python script, ‘chisel_verifier.py’, to continuously enumerate and test Chisel tunnel ports, ensuring the network’s functionality and resilience.

While the exact purpose of the operation remains uncertain, the scale of the network – 230 nodes – suggests a significant capability for delivering large volumes of email. The ongoing synchronization of the proxy list every five minutes indicates a continuous operation, raising concerns about potential misuse for activities such as spam or phishing. The discovery highlights the vulnerability of cloud infrastructure and the potential for threat actors to leverage compromised resources for malicious purposes.

Read the full article at The Hacker News