PCPJack is a cloud-focused threat actor and associated worm framework active by 2026 that targets exposed internet-facing infrastructure and cloud-native services for credential theft and post-compromise monetization. It is primarily associated with opportunistic compromise of Linux-based workloads hosted in major cloud environments, including Amazon Web Services, Google Cloud, and Microsoft Azure. PCPJack is notable for competing directly with TeamPCP: it has been observed terminating TeamPCP processes, removing TeamPCP artifacts from compromised hosts, and then harvesting npm, GitHub, and cloud credentials for its own use. PCPJack scans for exposed services such as Docker, Kubernetes, Redis, MongoDB, Ray, and related cloud-management surfaces, and has been reported exploiting multiple known vulnerabilities for initial access. After compromise, it deploys Linux tooling that supports persistence, credential theft, lateral spread, and operational reuse of victim infrastructure. Observed tradecraft includes use of Sliver for command and control, Chisel for reverse tunneling and SOCKS proxying, cron or systemd-based persistence, and automated validation of compromised hosts for downstream utility. A documented PCPJack operation converted at least 230 compromised cloud servers into a covert SMTP relay network. In that campaign, the actor used deterministic port assignment, continuous tunnel health checking, and SMTP capability verification to maintain a pool of working email proxies. The infrastructure management showed an organized post-exploitation workflow, including deployment state tracking, beacon filtering, relay verification, and synchronization of validated proxy inventories to downstream infrastructure. The ultimate use of the relay network was not conclusively established, but the architecture was consistent with large-scale email delivery operations such as spam or phishing enablement. PCPJack is best characterized as a financially motivated, cloud-opportunistic actor rather than a confirmed nation-state operator. Its tooling and victimology indicate a focus on scalable exploitation of exposed cloud infrastructure, theft of developer and cloud secrets, and monopolization of compromised environments by evicting rival malware. Some reporting has assessed with moderate confidence that PCPJack may have links to, or include a former affiliate of, TeamPCP due to overlap in targeting and familiarity with TeamPCP tooling, but that relationship is not conclusively established. No widely used sub-group designations are currently established beyond the PCPJack name itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newer credential- and secret-stealing worm that removes TeamPCP artifacts from compromised cloud infrastructure to displace a competing malware operator.
Rival activity cluster or worm operator targeting the same exposed cloud infrastructure as TeamPCP and removing TeamPCP tooling from compromised systems, possibly associated with a former TeamPCP operator.
Operated a 230-node cloud-based email relay network by compromising cloud servers and using them as monitored SMTP proxy infrastructure, likely for spam, phishing, or related email abuse.
Hijacked cloud and business servers to build a covert SMTP relay/proxy network, using compromised Linux hosts as email-capable proxies and syncing verified proxy lists to downstream infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.