PCPJack is not just hijacking cloud servers one by one. It appears to be running a reusable SMTP relay service, so the real risk is downstream mail abuse at scale: spam, phishing, and fraud that rides on compromised AWS, Google Cloud, and Azure infrastructure. The operator tooling looks maintained like a product, with synchronized proxy updates and checks for which relays still work.
Hunt.io found 230 hijacked business servers across the U.S., Europe, and Asia still operating as SMTP proxies and being synced to a downstream consumer every five minutes. It also found open C2 directories exposing source code, compiled binaries, deployment logs, scanning and exploitation tooling, plus a live Sliver configuration. That means cleaning a single VM may not end the abuse layer, because the same cloud hosts can keep being reused until they are removed from the relay pool.