PCPJack infrastructure exposed

Hunt.io has detailed new findings related to PCPJack, a credential theft framework previously documented by SentinelOne that spreads across exposed cloud infrastructure. While investigating PCPJack infrastructure nodes, Hunt.io researchers found poor attacker operational security, including publicly accessible directories. This allowed them to analyse the operators' tooling, including a Sliver-integrated deployment toolkit, a live Sliver command-and-control configuration, Chisel proxy binaries, and victim and configuration data, indicating victims across AWS, GCP and Azure-hosted Linux servers.

What this means for your organisation

The campaign targets cloud servers exposed to the internet, not employee machines. These are often the systems that sit outside ordinary endpoint management, without the same attention to hardening and logging. When the objective is credential theft, a single exposed test server becomes the entry point to production if keys are shared across environments.

Berigo recommends

  • Map which cloud Linux servers are actually exposed to the internet and close what does not need to be open.
  • Separate credentials and service accounts between test and production, and use short-lived credentials.
  • Ship system logs from cloud servers to a central location outside the server's own control.
  • Look for outbound connections to command-and-control tooling such as Sliver and tunnelling with Chisel.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch