Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-05

PCPJack

Also known as:XSync operator

As of 2026-06-07, PCPJack is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning threat intel, malware. Also known as XSync operator. ATT&CK coverage spans 51 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1068 (Exploitation for Privilege Escalation), T1105 (Ingress Tool Transfer), T1190 (Exploit Public-Facing Application).

Tracked threats
21 critical · 1 high
First seen
2026-05-07
Last seen
2026-06-07
ATT&CK techniques
51across 2 of 2 threats
Related CVEs
6Referenced by its activity
2 tracked threat(s) · Categories: THREAT_INTEL, MALWARE

Activity timeline

PCPJack appears in 2 tracked threats between and ; the busiest month was 2026-05 with 1 report.

ATT&CK techniques observed

51 techniques observed across 2 of 2 tracked threats · Command and Control (8), Credential Access (6), Discovery (5), Execution (4), Exfiltration (4), Persistence (4)
  • T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 2 of 2 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 2 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
  • T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
  • T1021.004 SSH — Lateral Movementobserved in 1 of 2 tracked threats
  • T1030 Data Transfer Size Limits — Exfiltrationobserved in 1 of 2 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 1 of 2 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1048 Exfiltration Over Alternative Protocol — Exfiltrationobserved in 1 of 2 tracked threats
  • T1049 System Network Connections Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1053 Scheduled Task/Job — Persistenceobserved in 1 of 2 tracked threats
  • T1053.003 Cron — Persistenceobserved in 1 of 2 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 1 of 2 tracked threats

Tracked threats

Related CVEs

6 CVEs referenced by tracked PCPJack activity