Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network

0
Medium
Published: 06/03/2026 (06/03/2026, 16:29:20 UTC)
Source: Reddit BlueTeam

Description

The PCPJack threat actor compromised approximately 230 cloud servers and repurposed them into a hidden SMTP relay network. The attacker left their deployment toolkit publicly accessible in an unauthenticated open directory, facilitating discovery and analysis. Indicators include a systemd service named xsync disguised as a system sync utility, files under /var/tmp/. xs, and Chisel reverse SOCKS5 tunnels on ports 10000-14999. A public blog post provides detailed MITRE ATT&CK mappings and HuntSQL detection queries. No official patch or remediation guidance is currently available.

Reddit Discussion

r/blueteamsec·posted by u/Straight-Practice-99
00

PCPJack's operator left their full deployment toolkit exposed on an open directory, no authentication required. Host IOCs include /var/tmp/.xs, a systemd service named xsync masquerading as a system sync utility, and Chisel reverse SOCKS5 tunnels on ports 10000-14999. MITRE ATT&CK mapping and HuntSQL queries included.

👉 Full breakdown and IOCs here: https://hunt.io/blog/pcpjack-230-cloud-servers-smtp-proxy-network-sliver-chisel

Also discussed in: r/Malware

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/10/2026, 16:46:34 UTC

Technical Analysis

PCPJack is a threat actor who compromised around 230 cloud servers to create a covert SMTP relay network. The attacker’s deployment toolkit was left exposed in an open directory without authentication, enabling defenders to analyze the tools used. Key indicators of compromise include a systemd service named xsync masquerading as a legitimate system sync utility, files located at /var/tmp/.xs, and Chisel reverse SOCKS5 tunnels operating on ports 10000-14999. The activity has been documented with MITRE ATT&CK framework mappings and detection queries published publicly. There is no vendor advisory or patch information available for this threat.

Potential Impact

The compromise of approximately 230 cloud servers allowed the attacker to establish a hidden SMTP relay network, which can be used to facilitate spam, phishing, or other malicious email activities. The exposure of the attacker’s deployment toolkit in an open directory increases the risk of replication or further exploitation by other threat actors. No direct patch or remediation is provided, so affected systems remain vulnerable to this unauthorized use.

Mitigation Recommendations

No official patch or remediation guidance is available. Defenders should leverage the published indicators of compromise, including the xsync systemd service, files at /var/tmp/.xs, and Chisel reverse SOCKS5 tunnels on ports 10000-14999, to detect and remove this threat. Utilize the provided MITRE ATT&CK mappings and HuntSQL queries from the referenced blog post for detection and response. Monitor for unauthorized SMTP relay activity and secure exposed directories to prevent similar exposures.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":30,"reasons":["external_link","newsworthy_keywords:compromised","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["compromised"],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a20575ae29bf47b50ce5b84

Added to database: 06/03/2026, 16:33:30 UTC

Last enriched: 06/10/2026, 16:46:34 UTC

Last updated: 07/28/2026, 11:29:02 UTC

Views: 114

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses