PCPJack Used 230 Cloud Linux Servers in a Hidden SMTP Relay Network

Summary
Hunt.io found exposed PCPJack infrastructure and deployment files showing 230 Sliver beacons were used to deploy Chisel SOCKS5 tunnels, qualify SMTP proxies, and sync verified proxies to a downstream server.
Key points
- Two unauthenticated directories on a server linked to PCPJack exposed deployment tools, state files, scanners, credential-harvesting tooling, and Sliver C2 configuration.
- A recovered version 3 state file records successful uploads and executions on 230 Sliver beacons; victim records include AWS, GCP, and Azure Linux servers.
- The toolkit deployed stock Chisel binaries as reverse SOCKS5 tunnels, with persistence through a systemd service for root users or a five-minute cron watchdog otherwise.
- An SMTP verification daemon tested tunnels against Gmail, enriched successful proxies with network details, and synced the verified list every five minutes to a separate server.
- The downstream server was inaccessible, so the proxies’ eventual use—such as spam or phishing—was not confirmed.
- Hunt.io linked the deployment infrastructure to PCPJack through a shared C2 address, but said the evidence does not prove operational continuity or a shared operator.
Article Details
- Attack Vectors
- PCPJack gains initial access through exploitation of public-facing web applications and establishes Sliver beacons on compromised Linux servers.
- The recovered toolkit deploys Chisel to those beacons, creating reverse SOCKS5 tunnels for an SMTP relay network.
- The payload persists as the dot-prefixed /var/tmp/.xs binary, using an xsync systemd service when running as root or a five-minute cron watchdog otherwise.
- A separate staging server contained pwnkit tooling associated with CVE-2021-4034 privilege escalation.
- Defensive Notes
- The article advises operators of Linux workloads on AWS, GCP, or Azure to check its listed indicators against their environments.
- The Chisel binaries are unmodified upstream builds, so their hashes may not trigger hash-based detections.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | englizm[.]online | Reverse-DNS name resolving to the host flagged for active Sliver activity. |
| HOSTNAME | vmi3053870[.]contaboserver[.]net | Reverse-DNS hostname of the downstream SMTP proxy-list server. |
| HOSTNAME | vmi3280867[.]contaboserver[.]net | Reverse-DNS hostname of the PCPJack-associated C2 server. |
| IPV4 | 213[.]136[.]80[.]73 | PCPJack-associated Sliver C2 and Chisel server that exposed the deployment toolkit. |
| IPV4 | 38[.]242[.]204[.]245 | Downstream server receiving verified SMTP proxy lists from the attacker toolkit. |
| IPV4 | 38[.]242[.]245[.]147 | Adjacent campaign infrastructure reported by SentinelOne as hosting a LastPass phishing domain. |
| IPV4 | 45[.]225[.]135[.]54 | Related staging server exposing C2 credentials, a Python HTTP C2 script, and privilege-escalation tooling. |
| IPV4 | 95[.]216[.]111[.]46 | Related host flagged for active Sliver activity. |
| URL | hxxp[:]//213[.]136[.]80[.]73:9000 | Chisel client connection URL specified in the deployment scripts. |
MITRE ATT&CK
T1036.004 · Masquerade Task or ServiceThe xsync service name is intended to resemble a routine Linux synchronization service.T1048 · Exfiltration Over Alternative ProtocolThe verifier synchronizes its verified proxy list by SCP to a separate downstream server.T1049 · System Network Connections DiscoveryThe verifier uses ss -tlnp to enumerate active Chisel tunnel ports.T1053.003 · CronNon-root deployments install a five-minute cron watchdog for the Chisel tunnel.T1057 · Process DiscoveryDeployment checks use pgrep to determine whether a Chisel tunnel is already running.T1059.004 · Unix ShellDeployers issue shell payloads to compromised Linux hosts through Sliver Execute RPC.T1090.003 · Multi-hop ProxyThe article maps the per-beacon reverse SOCKS5 proxies to this technique.T1190 · Exploit Public-Facing ApplicationThe article describes web application exploitation as PCPJack's initial-access method.T1543.002 · Systemd ServiceThe payload installs an xsync systemd service when it runs with root privileges.T1564.001 · Hidden Files and DirectoriesChisel binaries use dot-prefixed drop paths and persist as /var/tmp/.xs.T1572 · Protocol TunnelingChisel establishes an HTTP-wrapped reverse tunnel to the server on port 9000.T1583.003 · Virtual Private ServerThe article identifies Contabo VPS infrastructure hosting the C2 and tunnel aggregation servers.
CVE
People
Threat Actors
PCPJackDescribed by SentinelOne as a presumed former TeamPCP operator. Its C2 address overlaps with every recovered XSync deployment script, although the article says this does not prove operational continuity.TeamPCPCloud-focused threat actor whose artifacts PCPJack reportedly removes before installing its own Sliver beacon.
Vendors
Contabo GmbHHunt.io's AttackCapture File Manager surfaced 213.136.80[.]73 (Contabo GmbH, AS51167, Lauterbourg, France) hosting an open directory on port 8444Hetzner Online GmbH2 prior AttackCapture hits across two months, making it the highest priority. 95.216.111[.]46 (Hetzner Online GmbH, Finland, AS24940) came back with an Active Malware: Sliver flag and reverse DNS resolving toRACK SPHERE HOSTING S.A.within the last 30 days.Enriching those three IPs separated the signal quickly. 45.225.135[.]54 (RACK SPHERE HOSTING S.A., Netherlands, AS64107) carried 2 prior AttackCapture hits across two months, making it the
Products
AWS EC21 state file show a consistent target profile: cloud-hosted Linux servers running web applications. AWS EC2 instances (ip-172-31-*), GCP managed instance groups, and Azure-hosted VMs all appear. Named servers suchAzuretrue. Both verified proxies share the same exit IP - 48.217.21[.]105 (AS8075, Microsoft Corporation, Azure) - meaning two separate Chisel tunnels were active on the same victim host under different beacon IDs.GCPproxy, consistent with web application exploitation for initial access. Representative entries include a GCP managed instance group node (ddx-instance-group-1-4xfx, 35.223.238.76), an AWS Graviton instance inLinuxSentinelOne documented PCPJack in April 2026, covering how the campaign gains initial access and harvests credentials from compromised Linux servers. What that report didn't cover was what happens next.
Tools
AttackCaptureHunt.io's AttackCapture File Manager surfaced 213.136.80[.]73 (Contabo GmbH, AS51167, Lauterbourg, France) hosting an open directory on port 8444ChiselAll three Chisel binaries are unmodified stock builds from the public jpillora/chisel repository.chisel_verifier.pyof mail relay capability. Assessment: this is consistent with a decision to deploy broadly and let chisel_verifier.py handle SMTP filtering post-deployment.pwnkitport 8080 was more substantial: 79 files across 13 subdirectories totaling 4 MB. Key contents included a pwnkit/ directory with CVE-2021-4034 (834 KB across 7 files), a TLS certificate and private key pair for C2SliverA second open directory on port 9443 exposed the operator's live working directory, active scanners, exploitation tooling, and a Sliver C2 configuration, all accessible at the same time.
Countries
Finlandhits across two months, making it the highest priority. 95.216.111[.]46 (Hetzner Online GmbH, Finland, AS24940) came back with an Active Malware: Sliver flag and reverse DNS resolving to englizm.online.FranceHunt.io's AttackCapture File Manager surfaced 213.136.80[.]73 (Contabo GmbH, AS51167, Lauterbourg, France) hosting an open directory on port 8444Netherlandsthose three IPs separated the signal quickly. 45.225.135[.]54 (RACK SPHERE HOSTING S.A., Netherlands, AS64107) carried 2 prior AttackCapture hits across two months, making it the highest priority.