Executive Summary
In May 2026, the threat actor known as PCPJack hijacked 230 cloud servers across Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to establish a covert SMTP email relay network. The compromised servers, located in the U.S., Europe, and Asia, were transformed into SMTP proxies, verified for mail relay capabilities, and synchronized to a downstream consumer every five minutes. This operation enabled the threat actor to send large volumes of emails while concealing their origin, potentially facilitating spam campaigns, phishing attacks, or other malicious activities.
This incident underscores the increasing sophistication of cloud-based attacks and the critical need for robust security measures in cloud environments. Organizations must implement stringent access controls, regularly monitor for unauthorized activities, and ensure that all cloud services are properly configured to prevent exploitation by threat actors.
Why This Matters Now
The PCPJack incident highlights the urgent need for organizations to secure their cloud infrastructures against sophisticated threat actors who exploit misconfigurations to establish covert operations, such as unauthorized email relay networks.
Attack Path Analysis
PCPJack compromised cloud servers across AWS, Google Cloud, and Azure, escalating privileges to gain control over these systems. They moved laterally to hijack 230 servers, establishing a covert SMTP relay network. The adversary maintained command and control by syncing the compromised servers to a downstream consumer every five minutes. This setup facilitated the exfiltration of data through unauthorized email relays, impacting the confidentiality and integrity of the affected organizations' communications.
Kill Chain Progression
Initial Compromise
Description
PCPJack gained unauthorized access to cloud servers across AWS, Google Cloud, and Azure, likely through compromised cloud accounts.
Related CVEs
CVE-2024-27305
CVSS 5.3SMTP smuggling vulnerability in aiosmtpd allows remote attackers to send spoofed emails, facilitating advanced phishing attacks.
Affected Products:
Python Software Foundation aiosmtpd – < 1.4.5
Exploit Status:
proof of conceptCVE-2024-27938
CVSS 5.3SMTP smuggling vulnerability in Postal allows incoming emails to be spoofed, potentially facilitating phishing attacks.
Affected Products:
Postal Postal – < 3.0.0
Exploit Status:
proof of conceptCVE-2023-51765
CVSS 5.3SMTP smuggling vulnerability in Sendmail allows remote attackers to inject email messages with spoofed MAIL FROM addresses, bypassing SPF protection.
Affected Products:
Sendmail Consortium Sendmail – <= 8.17.2
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Compromise Infrastructure: Server
Resource Hijacking: Cloud Service Hijacking
Valid Accounts
Remote Services: Cloud Services
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing firewalls are documented, in use, and known to all affected parties.
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Cloud infrastructure compromise directly impacts IT services, requiring enhanced egress security, zero trust segmentation, and multicloud visibility to prevent SMTP relay hijacking.
Financial Services
SMTP relay networks threaten financial communications integrity, demanding encrypted traffic controls and anomaly detection to maintain HIPAA/PCI compliance requirements.
Health Care / Life Sciences
Compromised cloud servers risk patient data exfiltration through covert channels, necessitating threat detection capabilities and secure hybrid connectivity solutions.
Government Administration
Cross-regional server hijacking creates national security risks, requiring comprehensive cloud firewall protection and inline IPS capabilities for critical infrastructure defense.
Sources
- PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Networkhttps://thehackernews.com/2026/06/pcpjack-hijacks-230-aws-google-cloud.htmlVerified
- PCPJack Built a 230-Node Cloud SMTP Relay Network on Hijacked Servershttps://www.mallory.ai/stories/019e9664-cae4-747f-853d-f5b558156911Verified
- After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secretshttps://www.darkreading.com/cloud-security/teampcp-malware-pcpjack-steals-cloud-secretsVerified
- The Credential Worm That Evicts Its Rivals: A PCPJack Cloud Defense Playbookhttps://lyrie.ai/research/research/2026-05-11-22-deepdive-pcpjack-cloud-worm-docker-kubernetes-redis-credential-theft-defensive-playbookVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have significantly limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been constrained by enforcing strict identity-based access controls, reducing the likelihood of unauthorized entry.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited by enforcing strict segmentation policies, reducing the scope of accessible resources.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may have been significantly constrained, limiting their ability to compromise additional servers.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control communications could have been detected and disrupted, reducing their ability to coordinate compromised servers.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been blocked, preventing unauthorized data transfer out of the network.
The overall impact of the attack could have been significantly reduced, limiting the extent of data compromise and associated consequences.
Impact at a Glance
Affected Business Functions
- Email Communication
- Cloud Infrastructure Management
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of sensitive business communications and customer data due to unauthorized email relay.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within cloud environments.
- • Deploy East-West Traffic Security controls to monitor and restrict internal traffic, preventing unauthorized lateral movement.
- • Utilize Multicloud Visibility & Control solutions to gain comprehensive insights across cloud platforms and detect anomalous activities.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data exfiltration.
- • Establish Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious behaviors promptly.



