A threat actor called PCPJack hijacked 230 cloud servers across AWS, Google Cloud, and Azure, converting them into a covert SMTP relay network for spam. Researchers found the entire operation exposed on an unauthenticated server.
Threat actor PCPJack turned 230 hijacked cloud servers across AWS, Google Cloud, and Azure into a covert SMTP relay network. The operation was exposed after the group left their entire toolkit — including source code and Sliver configs — on an open C2 server.