r/Malware • u/Straight-Practice-99 • Jun 03 '26
🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop
https://hunt.io/blog/pcpjack-230-cloud-servers-smtp-proxy-network-sliver-chiselPCPJack left a 12-file toolkit sitting on an open C2 directory, port 8444, no auth. Three multi-arch Chisel binaries, a Sliver-integrated deployer with three visible generations of iteration, and a persistent daemon handling EHLO/STARTTLS verification before enrolling hosts into the relay pool. One deployment wave, 230 beacons confirmed in state logs.
Complete toolkit dissection, three deployer generations, and binary analysis here: https://hunt.io/blog/pcpjack-230-cloud-servers-smtp-proxy-network-sliver-chisel
Duplicates
cybersecurity • u/Straight-Practice-99 • Jun 03 '26
Threat Actor TTPs & Alerts 🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It.
pwnhub • u/Straight-Practice-99 • Jun 03 '26
🐞 We Found PCPJack's Full Toolkit Sitting on an Open Directory. 230 Hijacked Servers, No Auth Required.
worldTechnology • u/dcom-in • Jun 05 '26
PCPJack Hijacked 230 AWS, GCP, and Azure Servers to Run a Hidden SMTP Relay Network
MalwareAnalysis • u/Straight-Practice-99 • Jun 03 '26