# PCPJack

> As of 2026-06-07, PCPJack is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning threat intel, malware. Also known as XSync operator. ATT&CK coverage spans 51 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1068 (Exploitation for Privilege Escalation), T1105 (Ingress Tool Transfer), T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 2
- **Categories:** THREAT_INTEL, MALWARE
- **Also known as:** XSync operator
- **As of:** 2026-06-07

## ATT&CK techniques observed

51 techniques observed across 2 of 2 tracked threats. Tactics: Command and Control (8), Credential Access (6), Discovery (5), Execution (4), Exfiltration (4), Persistence (4).

- [T1068](https://intel.threadlinqs.com/technique/T1068) Exploitation for Privilege Escalation — Privilege Escalation — observed in 2 of 2 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 2 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 2 of 2 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 2 tracked threats
- [T1021.004](https://intel.threadlinqs.com/technique/T1021.004) SSH — Lateral Movement — observed in 1 of 2 tracked threats
- [T1030](https://intel.threadlinqs.com/technique/T1030) Data Transfer Size Limits — Exfiltration — observed in 1 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 1 of 2 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1048](https://intel.threadlinqs.com/technique/T1048) Exfiltration Over Alternative Protocol — Exfiltration — observed in 1 of 2 tracked threats
- [T1049](https://intel.threadlinqs.com/technique/T1049) System Network Connections Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Persistence — observed in 1 of 2 tracked threats
- [T1053.003](https://intel.threadlinqs.com/technique/T1053.003) Cron — Persistence — observed in 1 of 2 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 2 tracked threats

## Tracked threats

- [PCPJack Covert SMTP Relay Network — 230 Hijacked AWS/Google Cloud/Azure Servers via Sliver C2 + Chisel SOCKS Tunneling](https://intel.threadlinqs.com/threat/TL-2026-0701) — HIGH
- [PCPJack Worm — Cloud Credential Theft Framework Evicting TeamPCP Infections (CVE-2025-29927, CVE-2025-55182, CVE-2026-1357, CVE-2025-9501, CVE-2025-48703)](https://intel.threadlinqs.com/threat/TL-2026-0478) — CRITICAL

## Related CVEs

6 CVEs referenced by tracked PCPJack activity.

- [CVE-2026-1357](https://intel.threadlinqs.com/cve/CVE-2026-1357)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-48703](https://intel.threadlinqs.com/cve/CVE-2025-48703)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/PCPJack
