Also known as: worm.py, tracked as, an orchestrator script, Azure, Cloudflare, Cloudfront, Fastly, Kubernetes, MongoDB, RayML, Redis services, described below, SocksBot, Carbanak, which are tracked differently, TeamPCP, Coroxy
PCPJack operators compromised roughly 230 Linux cloud instances in a rapid scaling campaign that spanned Amazon Web Services, Google Cloud Platform, and Microsoft Azure. The attackers used exposed directories on a public IP (213.136.80.73) to host a full deployment toolkit comprising Chisel binaries, custom Python deployers, and operational state files. Their end‑to‑end operation began with initial access via exploitation of cloud‑hosted web applications, followed by the installation of lightweight systemd units (e.g., sys-monitor.service) and bootstrap.sh scripts that maintained persistence as root services. Once in place, PCPJack rapidly propagated through containerized workloads by enumerating Kubernetes namespaces, pods, secrets, and ConfigMaps with service account tokens, then leveraged exposed Docker sockets to inject cron jobs and persist across host reboots. The group utilized Sliver C2 beacons and Python‑based remote file copy scripts (T1105) to upload additional modules and establish reverse SOCKS5 tunnels on compromised hosts. Persistent SMTP relays were configured and synchronized with a downstream aggregation server every five minutes, enabling the actor’s primary credential‑theft and email‑based attack vector. Throughout this campaign PCPJack demonstrated advanced defense evasion tactics: it deleted legacy TeamPCP binaries, base64‑decoded Kubernetes secrets for credential harvesting, encrypted stolen data with custom utilities (crypto_util.py), and exfiltrated data over HTTPS to a typosquatted CloudFront domain or via Telegram. The operatives also scanned public cloud IP ranges using cloud_ranges.py, targeting exposed Redis, MongoDB, RayML, and Docker services for further lateral movement. Overall, the campaign shows a clear pattern of rapid expansion across multi‑cloud environments, blending credential‑stealing, propagation, and covert SMTP relay techniques to maximize financial gain while minimizing detection.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
PCPJack is a sophisticated, financially driven threat actor that exploits exposed cloud services to deploy a covert SMTP relay network and harvest credentials from containerized workloads across AWS, GCP, and Azure. The group leverages a custom Python‑based framework—worm.py/monitor.py—to propagate rapidly through Kubernetes, Docker, Redis, MongoDB, and RayML environments, establishing persistence via bootstrap scripts and systemd services while actively removing legacy TeamPCP artifacts to evade detection.
Goals & Targeting
PCPJack’s strategic objectives revolve around generating revenue through phishing, exfiltration of high‑volume credentials, and exploitation of compromised infrastructure as an SMTP relay for malicious email campaigns. Their targeting profile is broad yet focused on organizations with cloud‑hosted web applications—including small to medium enterprises—spanning financial services, defense, pharmaceutical, mining, IT, media, government, energy, legal, non‑profit, telecommunications, and construction sectors. The operation shows a preference for German entities (DE) but has proven capable of scaling across multiple jurisdictions. The mix of credential theft, lateral movement within containerised ecosystems, and SMTP relay deployment indicates an emphasis on both immediate attack surface amplification (via compromised email relays) and long‑term data harvesting. By maintaining stealth through artifact removal, obfuscation, and encrypted exfiltration, PCPJack seeks to sustain its financial operations over time while minimizing the risk of attribution to a known threat group beyond TeamPCP. Their approach suggests an adaptive mindset: they exploit open or misconfigured cloud services, leverage common APIs for rapid deployment, and dynamically adjust tactics (e.g., switching from Python deployers to Chisel tunnels) when defensive controls surface. The financial motivations drive the selection of victims with valuable credentials and the use of SMTP relays as a low‑effort, high‑impact secondary vector. In sum, PCPJack is opportunistic yet methodical—using cloud misconfiguration as a launchpad for credential theft, lateral compromise, and a covert email network designed to facilitate further attacks or monetisation.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The PCPJack campaign has unfolded in a rapid, multi‑cloud expansion covering approximately 230 Linux instances across AWS, GCP, and Azure. The attackers initiated compromise by exploiting exposed web application endpoints, then established persistence as root through systemd services and cron jobs that invoke bootstrap.sh scripts. Their operations center on building an SMTP relay network for email delivery of malicious payloads while harvesting credentials from a wide range of cloud services—including MongoDB, Redis, RayML, Kubernetes secrets, and IMDS endpoints. The operation exhibits several notable patterns: (1) a staged growth approach with three deployment versions scaling from 50 to 230 nodes; (2) synchronized proxy relays updated every five minutes; (3) proactive removal of legacy TeamPCP artifacts to obfuscate presence; (4) use of custom Python scripts and utilities for credential extraction, encryption, and exfiltration; and (5) exploitation of public cloud IP ranges identified through automated scans. The actors target primarily small- to medium‑size businesses with cloud‑hosted services across diverse sectors but show no preference for a particular industry beyond the financial motivation. The campaign’s operational tempo is high‑velocity, leveraging automated scripts for scanning, deployment, and exfiltration. However, the group remains careful, using encryption and deletion of artifacts to stay beneath detection thresholds. The use of both Sliver and potentially Cobalt Strike backends indicates modularity and the ability to pivot to different C2 frameworks. All evidence points to a well‑structured threat actor capable of rapid expansion across cloud environments while maintaining persistence and data exfiltration capabilities, driven primarily by financial motives.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a detailed picture of PCPJack’s techniques, tools, and operational patterns, but several gaps remain. Dates of first and last activity are not publicly documented, limiting the ability to assess evolution over time or current relevance. The exact connection between the observed TeamPCP artifact removal and broader attribution beyond the alias remains speculative without additional forensic evidence. While financial motivation is clearly indicated through email relay exploitation and credential theft, metrics on revenue generation or specific monetization channels are lacking. Consequently, confidence in the technical assessment is high, but uncertainty exists around temporal context, ultimate actors behind the operations, and precise economic impact.
No campaigns linked yet.
No observed data linked yet.
12
Techniques
56
Tools
0
Campaigns
41
IOCs
0
Observed Data
7
Tactics