# PCPJack Malware: Cloud-Targeting Evolution Steals Credentials Using Deceptive Parquet File Technique


A newly discovered malware variant called PCPJack is targeting cloud environments with a sophisticated approach to credential theft and lateral movement. Succeeding the previously documented TeamPCP malware, PCPJack leverages parquet files—a data serialization format commonly used in big data environments—as a stealthy mechanism for target discovery and validation before launching its main attack payload.


The malware demonstrates advanced operational security practices and marks a worrying evolution in cloud-focused attack strategies that prioritize precision targeting over broad-based scanning.


## The Threat


PCPJack is a cloud-focused malware designed to infiltrate multi-cloud environments and exfiltrate sensitive credentials and secrets. The malware's primary objectives include:


  • Credential harvesting — Extracting cloud API keys, authentication tokens, and secret management credentials
  • Lateral movement — Using stolen credentials to pivot across cloud accounts and services
  • Reconnaissance — Mapping cloud infrastructure and identifying high-value targets
  • Persistence — Establishing footholds within cloud environments for long-term access

  • What distinguishes PCPJack from earlier cloud malware is its approach to target validation. Rather than indiscriminately scanning cloud environments, the malware uses parquet files—a columnar storage format favored by data analytics platforms—to conduct pre-validated discovery. This suggests the attackers have invested significant effort into understanding how their targets operate and which infrastructure elements are most valuable.


    The malware reportedly targets organizations across multiple cloud platforms, including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP), making it a pan-cloud threat rather than platform-specific.


    ## Background and Context


    PCPJack represents an evolutionary step from TeamPCP, malware that was first documented in earlier security research. The transition from TeamPCP to PCPJack reflects a common pattern in the malware ecosystem: threat actors continuously refine their tools based on defender feedback, incident response findings, and their own operational experience.


    ### The TeamPCP Lineage


    TeamPCP was previously documented as a malware family targeting cloud infrastructures with a focus on:

  • Stealing credentials from cloud platforms
  • Accessing cloud-native secret management systems
  • Leveraging compromised cloud accounts for botnet activities and cryptomining

  • The shift to PCPJack suggests several tactical improvements:

  • Reduced detection footprint — The use of parquet files and less obvious behavioral patterns
  • Better targeting precision — Pre-validated target selection reduces noise and detection risk
  • Enhanced cloud environment knowledge — Understanding of cloud-native architectures and data formats

  • ### Why Parquet Files Matter


    Parquet is an open-source columnar storage format designed for efficient data compression and analysis in big data frameworks like Apache Spark and Hadoop. The choice is significant because:


    1. Legitimacy — Parquet files are ubiquitous in data engineering and analytics workflows, making them less suspicious

    2. Data efficiency — They can encode substantial information about target infrastructure in a compact format

    3. Parsing complexity — Security tools may be less equipped to inspect parquet file contents compared to text-based formats

    4. Integration — Many cloud environments have native support for parquet, making them easier to deploy and execute within cloud workflows


    ## Technical Details


    ### Attack Methodology


    PCPJack's operational approach appears to follow a reconnaissance-validation-exploitation cycle:


    Phase 1: Discovery and Staging

  • The malware gains initial access through compromised credentials, supply chain attacks, or vulnerable cloud APIs
  • It begins mapping the target's cloud environment, identifying compute instances, storage buckets, and secret management systems

  • Phase 2: Parquet-Based Validation

  • The malware generates or deploys parquet files containing encoded information about potential targets
  • These files serve as a "pre-validated target list," filtering infrastructure elements by value and accessibility
  • The columnar format allows efficient queries of large datasets without loading entire files into memory

  • Phase 3: Credential Extraction

  • Using the validated target information, PCPJack focuses credential harvesting efforts on high-priority systems
  • It targets:
  • - AWS IAM credentials and temporary session tokens

    - Azure service principals and managed identities

    - GCP service account keys

    - Database connection strings and API keys stored in secret managers


    Phase 4: Lateral Movement and Persistence

  • Stolen credentials are used to access additional resources
  • The malware may establish persistence through cloud-native mechanisms (Lambda functions, scheduled tasks, etc.)

  • ### Key Indicators of Compromise (IOCs)


    Organizations should monitor for:

  • Unusual parquet file creation or access in cloud storage services
  • Unexpected authentication attempts using service account credentials
  • Privilege escalation activity from previously dormant accounts
  • Exfiltration of environment variables or configuration files containing secrets
  • Unexpected compute resource spawning (instances, containers) configured for data exfiltration

  • ## Implications for Organizations


    ### Who Is at Risk


    PCPJack presents particular risk to organizations with:


    | Risk Factor | Reason |

    |------------|--------|

    | Multi-cloud deployments | Broader attack surface across AWS, Azure, and GCP |

    | Shared cloud infrastructure | Lateral movement risk across business units |

    | Weak secret rotation policies | Long-lived credentials increase value of theft |

    | Legacy credential storage | Hardcoded secrets in configuration files or repositories |

    | Data analytics workloads | Native parquet file usage may mask malicious activity |


    ### Business and Security Impact


  • Credential compromise leading to unauthorized resource access and billing fraud
  • Data exfiltration of sensitive business intelligence or customer information
  • Cryptomining operations consuming cloud resources and inflating infrastructure costs
  • Compliance violations if compromised cloud environments contain regulated data
  • Supply chain risk if attackers use compromised accounts to pivot to customer or partner environments

  • ## Recommendations


    ### Immediate Actions (First 30 Days)


    1. Inventory all cloud credentials and secrets

    - Identify where credentials are stored (environment variables, configuration files, secret managers)

    - Document which services and teams have access to cloud credentials


    2. Rotate all potentially exposed credentials

    - Force rotation of IAM users, service account keys, and API tokens

    - Implement automatic credential expiration policies


    3. Enable comprehensive audit logging

    - Ensure CloudTrail (AWS), Azure Activity Log, and GCP Audit Logs are enabled

    - Configure alerts for suspicious authentication patterns


    4. Audit parquet file activity

    - Search cloud storage for unusual parquet files

    - Review access logs for parquet files in data lakes and analytics workloads


    ### Medium-Term Hardening (30-90 Days)


  • Implement secrets management using AWS Secrets Manager, Azure Key Vault, or HashiCorp Vault
  • Enforce MFA on all human and service account authentications
  • Deploy endpoint detection and response (EDR) tools to identify malware execution
  • Restrict service account permissions using principle of least privilege
  • Implement network segmentation to limit lateral movement between cloud resources

  • ### Long-Term Resilience


  • Adopt a zero-trust cloud architecture requiring continuous verification of all access requests
  • Establish secrets rotation schedules with automated enforcement
  • Deploy cloud-native security tools that understand parquet files and other data serialization formats
  • Conduct regular red team exercises simulating multi-cloud attack scenarios
  • Maintain immutable backup copies of critical cloud configurations outside primary cloud environments

  • ---


    ## HackWire Analysis


    The emergence of PCPJack represents a meaningful sophistication in cloud-targeted malware development. The deliberate choice to use parquet files for target pre-validation suggests threat actors have moved beyond opportunistic scanning toward a precision-focused approach to cloud attacks. This is not random malware—this is purpose-built.


    What makes this significant *now* is the explosion of multi-cloud deployments. Organizations rushing to adopt cloud-native architectures often inherit fragmented security postures, with credentials scattered across configuration files, CI/CD pipelines, and ad-hoc secret storage. PCPJack is built to exploit exactly this chaos. The use of parquet files is elegant from a defender-evasion perspective: they're ubiquitous in modern data stacks, legitimate to find, and complex enough that most security tools treat them as "data" rather than "threat vectors."


    The TeamPCP → PCPJack evolution also signals a maturing threat actor. Previous cloud malware was often crude, relying on brute-force scanning and high-visibility exfiltration. PCPJack's approach—pre-validate targets, focus credential harvesting, minimize detection noise—is the trademark of experienced operators or well-resourced teams. This could indicate nation-state involvement, organized cybercriminal gangs, or both.


    For defenders, the pattern recognition here is critical: as malware becomes more cloud-native, security controls must move from endpoint-focused thinking toward cloud-aware detection. Monitoring for unusual parquet file operations, unexpected data serialization format parsing, and credential material appearing in non-standard formats should become routine.


    The concrete next step: treat secrets rotation as non-negotiable infrastructure, not a compliance checkbox. Organizations that can rotate all cloud credentials in under 48 hours—that have automated, tested rotation pipelines—will significantly raise the cost of PCPJack attacks. Those that cannot will remain high-value targets.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)