PCPJack
PCPJack is a cloud-focused threat actor/framework documented by SentinelOne/SentinelLABS in 2026. The content describes PCPJack as a cloud worm and credential-theft framework that scans for exposed Docker, Kubernetes, Redis, MongoDB, and RayML services, exploits five vulnerabilities for initial access, and then harvests npm, GitHub, and cloud credentials. SentinelLABS also reported that PCPJack terminates TeamPCP processes and removes TeamPCP artifacts from compromised environments before spreading laterally. SentinelLABS assessed with moderate confidence that PCPJack may be operated by a former TeamPCP affiliate based on overlap with the December 2025 PCPCat phase. Separate reporting attributed to PCPJack an active Linux post-compromise operation that hijacked cloud servers associated with AWS, Google Cloud, and Microsoft Azure and converted compromised business servers in the U.S., Europe, and Asia into a covert SMTP relay network. The recovered toolkit used Sliver implants and Chisel tunneling to deploy SMTP-capable proxies across Linux AMD64, ARM64, and x86 systems. Victim-side binaries were dropped as hidden files and persisted at /var/tmp/.xs, with persistence established either as a systemd service named xsync or via a five-minute cron watchdog. Deployer scripts loaded Sliver client configuration, filtered recently active Linux beacons, assigned deterministic SOCKS5 ports in the 10000-14999 range from beacon UUIDs, and in earlier versions tested outbound access to smtp.gmail.com:587 before deployment. A verifier daemon continuously enumerated active tunnel ports, tested SMTP capability via EHLO and STARTTLS, enriched working proxies with exit IP, country, and ASN data, and synchronized verified proxy lists to downstream infrastructure. State artifacts showed at least one completed deployment wave affecting 230 Linux beacons in March 2026. Known alias in the provided content: pcpjack.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Tradecraft
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hijacked cloud and business servers to build a covert SMTP relay/proxy network, using compromised Linux hosts as email-capable proxies and syncing verified proxy lists to downstream infrastructure.
Cloud-focused intrusion activity tied to compromised Linux servers. In this content, PCPJack is associated with initial access, credential harvesting from Linux servers, and operation of Sliver/Chisel-backed infrastructure that supports large-scale SOCKS5/SMTP proxy deployment.
A separate named threat framework that removes TeamPCP artifacts from compromised environments, then spreads laterally to steal additional cloud credentials.
A rival cloud worm that removes TeamPCP artifacts from compromised environments and then steals npm, GitHub, and cloud credentials; assessed with moderate confidence as possibly operated by a former TeamPCP affiliate.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.