PCPJack Used 230 Cloud Linux Servers in a Hidden SMTP Relay Network

· Original article ↗

Summary

Hunt.io found exposed PCPJack infrastructure and deployment files showing 230 Sliver beacons were used to deploy Chisel SOCKS5 tunnels, qualify SMTP proxies, and sync verified proxies to a downstream server.

Key points

  • Two unauthenticated directories on a server linked to PCPJack exposed deployment tools, state files, scanners, credential-harvesting tooling, and Sliver C2 configuration.
  • A recovered version 3 state file records successful uploads and executions on 230 Sliver beacons; victim records include AWS, GCP, and Azure Linux servers.
  • The toolkit deployed stock Chisel binaries as reverse SOCKS5 tunnels, with persistence through a systemd service for root users or a five-minute cron watchdog otherwise.
  • An SMTP verification daemon tested tunnels against Gmail, enriched successful proxies with network details, and synced the verified list every five minutes to a separate server.
  • The downstream server was inaccessible, so the proxies’ eventual use—such as spam or phishing—was not confirmed.
  • Hunt.io linked the deployment infrastructure to PCPJack through a shared C2 address, but said the evidence does not prove operational continuity or a shared operator.

Article Details

Attack Vectors
  • PCPJack gains initial access through exploitation of public-facing web applications and establishes Sliver beacons on compromised Linux servers.
  • The recovered toolkit deploys Chisel to those beacons, creating reverse SOCKS5 tunnels for an SMTP relay network.
  • The payload persists as the dot-prefixed /var/tmp/.xs binary, using an xsync systemd service when running as root or a five-minute cron watchdog otherwise.
  • A separate staging server contained pwnkit tooling associated with CVE-2021-4034 privilege escalation.
Defensive Notes
  • The article advises operators of Linux workloads on AWS, GCP, or Azure to check its listed indicators against their environments.
  • The Chisel binaries are unmodified upstream builds, so their hashes may not trigger hash-based detections.

Indicators of compromise

TypeIndicatorContext
DOMAINenglizm[.]onlineReverse-DNS name resolving to the host flagged for active Sliver activity.
HOSTNAMEvmi3053870[.]contaboserver[.]netReverse-DNS hostname of the downstream SMTP proxy-list server.
HOSTNAMEvmi3280867[.]contaboserver[.]netReverse-DNS hostname of the PCPJack-associated C2 server.
IPV4213[.]136[.]80[.]73PCPJack-associated Sliver C2 and Chisel server that exposed the deployment toolkit.
IPV438[.]242[.]204[.]245Downstream server receiving verified SMTP proxy lists from the attacker toolkit.
IPV438[.]242[.]245[.]147Adjacent campaign infrastructure reported by SentinelOne as hosting a LastPass phishing domain.
IPV445[.]225[.]135[.]54Related staging server exposing C2 credentials, a Python HTTP C2 script, and privilege-escalation tooling.
IPV495[.]216[.]111[.]46Related host flagged for active Sliver activity.
URLhxxp[:]//213[.]136[.]80[.]73:9000Chisel client connection URL specified in the deployment scripts.

MITRE ATT&CK

CVE

People

Threat Actors

Vendors

Products

Tools

Countries

Related Articles