🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network
The PCPJack threat actor compromised approximately 230 cloud servers and repurposed them into a hidden SMTP relay network. The attacker left their deployment toolkit publicly accessible in an unauthenticated open directory, facilitating discovery and analysis. Indicators include a systemd service named xsync disguised as a system sync utility, files under /var/tmp/. xs, and Chisel reverse SOCKS5 tunnels on ports 10000-14999. A public blog post provides detailed MITRE ATT&CK mappings and HuntSQL detection queries. No official patch or remediation guidance is currently available.
AI Analysis
Technical Summary
PCPJack is a threat actor who compromised around 230 cloud servers to create a covert SMTP relay network. The attacker’s deployment toolkit was left exposed in an open directory without authentication, enabling defenders to analyze the tools used. Key indicators of compromise include a systemd service named xsync masquerading as a legitimate system sync utility, files located at /var/tmp/.xs, and Chisel reverse SOCKS5 tunnels operating on ports 10000-14999. The activity has been documented with MITRE ATT&CK framework mappings and detection queries published publicly. There is no vendor advisory or patch information available for this threat.
Potential Impact
The compromise of approximately 230 cloud servers allowed the attacker to establish a hidden SMTP relay network, which can be used to facilitate spam, phishing, or other malicious email activities. The exposure of the attacker’s deployment toolkit in an open directory increases the risk of replication or further exploitation by other threat actors. No direct patch or remediation is provided, so affected systems remain vulnerable to this unauthorized use.
Mitigation Recommendations
No official patch or remediation guidance is available. Defenders should leverage the published indicators of compromise, including the xsync systemd service, files at /var/tmp/.xs, and Chisel reverse SOCKS5 tunnels on ports 10000-14999, to detect and remove this threat. Utilize the provided MITRE ATT&CK mappings and HuntSQL queries from the referenced blog post for detection and response. Monitor for unauthorized SMTP relay activity and secure exposed directories to prevent similar exposures.
🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network
Description
The PCPJack threat actor compromised approximately 230 cloud servers and repurposed them into a hidden SMTP relay network. The attacker left their deployment toolkit publicly accessible in an unauthenticated open directory, facilitating discovery and analysis. Indicators include a systemd service named xsync disguised as a system sync utility, files under /var/tmp/. xs, and Chisel reverse SOCKS5 tunnels on ports 10000-14999. A public blog post provides detailed MITRE ATT&CK mappings and HuntSQL detection queries. No official patch or remediation guidance is currently available.
Reddit Discussion
PCPJack's operator left their full deployment toolkit exposed on an open directory, no authentication required. Host IOCs include /var/tmp/.xs, a systemd service named xsync masquerading as a system sync utility, and Chisel reverse SOCKS5 tunnels on ports 10000-14999. MITRE ATT&CK mapping and HuntSQL queries included.
👉 Full breakdown and IOCs here: https://hunt.io/blog/pcpjack-230-cloud-servers-smtp-proxy-network-sliver-chisel
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
PCPJack is a threat actor who compromised around 230 cloud servers to create a covert SMTP relay network. The attacker’s deployment toolkit was left exposed in an open directory without authentication, enabling defenders to analyze the tools used. Key indicators of compromise include a systemd service named xsync masquerading as a legitimate system sync utility, files located at /var/tmp/.xs, and Chisel reverse SOCKS5 tunnels operating on ports 10000-14999. The activity has been documented with MITRE ATT&CK framework mappings and detection queries published publicly. There is no vendor advisory or patch information available for this threat.
Potential Impact
The compromise of approximately 230 cloud servers allowed the attacker to establish a hidden SMTP relay network, which can be used to facilitate spam, phishing, or other malicious email activities. The exposure of the attacker’s deployment toolkit in an open directory increases the risk of replication or further exploitation by other threat actors. No direct patch or remediation is provided, so affected systems remain vulnerable to this unauthorized use.
Mitigation Recommendations
No official patch or remediation guidance is available. Defenders should leverage the published indicators of compromise, including the xsync systemd service, files at /var/tmp/.xs, and Chisel reverse SOCKS5 tunnels on ports 10000-14999, to detect and remove this threat. Utilize the provided MITRE ATT&CK mappings and HuntSQL queries from the referenced blog post for detection and response. Monitor for unauthorized SMTP relay activity and secure exposed directories to prevent similar exposures.
Technical Details
- Source Type
- Subreddit
- blueteamsec+AskNetsec+Information_Security
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":30,"reasons":["external_link","newsworthy_keywords:compromised","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["compromised"],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a20575ae29bf47b50ce5b84
Added to database: 06/03/2026, 16:33:30 UTC
Last enriched: 06/10/2026, 16:46:34 UTC
Last updated: 07/28/2026, 11:29:02 UTC
Views: 114
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.