PCPJack is a cloud-focused credential-stealing worm and threat actor active in 2026 that targets exposed cloud-native infrastructure and developer-facing services. It is associated with opportunistic compromise of internet-exposed Docker, Kubernetes, Redis, MongoDB, and Ray environments, using known vulnerabilities for initial access and then harvesting cloud, GitHub, and npm credentials from compromised hosts. Multiple reports describe PCPJack as a rival or copycat operation overlapping with TeamPCP’s victim space, and it is notable for actively terminating TeamPCP processes and removing TeamPCP artifacts from infected systems to monopolize access. PCPJack has been linked to campaigns against cloud servers hosted in major public cloud environments including Amazon Web Services, Google Cloud, and Microsoft Azure. In one documented operation, the actor converted hundreds of compromised Linux cloud servers into a covert SMTP relay network. That infrastructure used Sliver for command and control and Chisel-based reverse SOCKS tunneling to transform infected hosts into monitored email-capable proxies. The deployment workflow included host validation, deterministic proxy-port assignment, persistence through cron or systemd, and continuous tunnel verification to maintain a usable relay pool. The actor’s tooling and tradecraft indicate emphasis on automated scanning, exploitation, credential theft, persistence, post-compromise host management, and defense evasion. PCPJack scans for exposed services, exploits vulnerabilities for footholds, removes competing malware, steals secrets from cloud and developer environments, and maintains durable access on Linux systems. Recovered tooling also showed structured operational workflows for beacon selection, staged deployment, health checks, and relay verification. The downstream use of the SMTP proxy network has not been conclusively established, though large-scale email delivery activity such as spam or phishing is a plausible use case. PCPJack is widely discussed in relation to TeamPCP because of direct artifact removal and infrastructure contention. Some assessments suggest the operator may be a former TeamPCP affiliate or someone familiar with TeamPCP tooling, but that attribution remains unconfirmed. High-confidence reporting supports describing PCPJack as an opportunistic cloud-intrusion and credential-theft actor with anti-competitor behavior and secondary use of compromised infrastructure for covert relay operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newer credential- and secret-stealing worm that removes TeamPCP artifacts from compromised cloud infrastructure to displace a competing malware operator.
Rival activity cluster or worm operator targeting the same exposed cloud infrastructure as TeamPCP and removing TeamPCP tooling from compromised systems, possibly associated with a former TeamPCP operator.
Operated a 230-node cloud-based email relay network by compromising cloud servers and using them as monitored SMTP proxy infrastructure, likely for spam, phishing, or related email abuse.
Hijacked cloud and business servers to build a covert SMTP relay/proxy network, using compromised Linux hosts as email-capable proxies and syncing verified proxy lists to downstream infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.