FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity·High

Hackers Turn Cloud Servers Into a Secret Mail Network

Hackers Turn Cloud Servers Into a Secret Mail Network
AWS logo
AWS news →

TL;DR: A threat actor called PCPJack has hijacked over 230 servers on AWS, Google Cloud, and Azure. The compromised servers are being used to create a covert email relay network, turning them into proxies for sending mail.

By Neeraj Dhiman·3h ago·2 min read·updated 1h ago
Source

Key facts

Category
Cybersecurity
Impact
High
Published
3h ago
Source
The Hacker News

Full summary

A threat actor has hijacked hundreds of AWS, Google Cloud, and Azure servers to build a covert network for sending emails.

A threat actor identified as PCPJack has successfully compromised over 230 cloud servers across Amazon Web Services (AWS), Google Cloud, and Microsoft Azure. According to security researchers, these hijacked servers, located in the U.S., Europe, and Asia, have been secretly converted into an email relay network. The attackers repurpose the servers to function as Simple Mail Transfer Protocol (SMTP) proxies, which are systems designed to send emails on behalf of others. The compromised machines are verified for their mail relay capabilities and then synchronized with a central controller every five minutes. This creates a distributed and resilient infrastructure for the attacker to send large volumes of email from seemingly legitimate sources.

This campaign poses a significant risk to any organization using major cloud platforms. When a server is hijacked for a malicious relay network, the consequences can be severe. The server's IP address can quickly be added to email blacklists, which would block your own legitimate business emails from reaching customers and partners. This can disrupt communications and damage your company's reputation, as your infrastructure becomes associated with spam or phishing campaigns. Furthermore, the unauthorized activity consumes computing resources, leading to unexpected increases in your cloud service bills. The covert nature of the attack means it can go undetected for long periods, silently causing harm.

The PCPJack operation highlights a broader trend of attackers abusing trusted cloud infrastructure to evade security defenses. By routing their malicious traffic through reputable providers like AWS and Google Cloud, they bypass spam filters and security gateways that are more likely to scrutinize traffic from unknown or suspicious IP addresses. This makes their campaigns far more effective. For security and IT teams, this incident underscores the critical need for vigilant monitoring of cloud environments. It is essential to track outbound network traffic, regularly audit server configurations for unauthorized software, and implement strict firewall policies to prevent systems from being co-opted for such attacks.

Why it matters

Attackers are abusing the trusted reputation of major cloud providers to bypass security filters, making their malicious email campaigns more effective and harder to detect.

Business impact

A compromised server can lead to blacklisted IPs, preventing legitimate emails from being delivered, and cause reputational damage if your company's infrastructure is used for spam or phishing.

Action checklist

  1. 1Monitor outbound SMTP traffic for unusual patterns or volume.
  2. 2Review server configurations for unauthorized software or proxy services.
  3. 3Implement strict egress firewall rules to limit outbound connections to only what is necessary.
  4. 4Regularly check if your server IP addresses have been added to email blacklists.

Tags

#aws#google cloud#cybersecurity#malware#azure#cloud security

Related on Notifire

  • ResearchKubernetes security
  • ResearchSupply-chain security
  • ResearchCritical CVEs of 2026
  • CompareSSO vs SCIM

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Related stories

Primary source: The Hacker News

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube