PCPJack spreads through cloud estates and steals credentials
SentinelLABS has identified PCPJack, a credential theft framework that worms across exposed cloud infrastructure while removing artifacts tied to the threat actor TeamPCP. The toolset harvests credentials from cloud, container, developer, productivity and financial services and exfiltrates the data through attacker-controlled infrastructure. Targets include exposed Docker, Kubernetes, Redis, MongoDB, RayML and vulnerable web applications. Unlike typical cloud malware, it deploys no cryptominers; the mix of services it targets points to fraud, extortion or resale of stolen access.
What this means for your organisation
This does not hit those with a deliberate cloud architecture, but those with a forgotten one. A test environment with an open Docker API or a Redis without a password is enough to gain a foothold, and from there the toolset moves laterally. And because what is stolen is credentials rather than compute, nothing shows up on your bill. The consequence arrives later, as unauthorised access somewhere else entirely.
Berigo recommends
- Map what you actually expose to the internet in the cloud, including test and development environments nobody watches any more.
- Close off management interfaces for Docker, Kubernetes, Redis and MongoDB from the open internet, without exception.
- Give workloads short-lived, narrowly scoped credentials instead of long-lived keys.
- Alert on use of cloud credentials from unexpected locations or at unusual hours.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch