Researchers report a new malware framework named PCPJack that targets exposed cloud and application environments. Multiple outlets say the toolset primarily focuses on credential theft, harvesting authentication material from cloud, container, developer, productivity, and financial services. The framework then exfiltrates stolen information to attacker-controlled infrastructure.
Bleeping Computer and SecurityWeek state that PCPJack also actively removes or cleans artifacts associated with a prior malware family called TeamPCP. Dark Reading adds detail on how PCPJack conducts discovery and targeting, including the use of parquet files for stealthy, pre-validated identification of systems to reach across environments.
The Hacker News reports that PCPJack is worm-like in its spread and references exploitation of multiple vulnerabilities, citing five CVEs as part of its ability to move across cloud systems. Overall, the disclosures describe PCPJack as operating across several platforms and management layers, including AWS and container orchestration components such as Docker and Kubernetes, while both stealing credentials and eliminating TeamPCP-related traces.