Group-IB identified a China-nexus cyber operation, tracked as JadeProx, which has been targeting government, healthcare, and education sectors across Asia and Latin America. The operation utilizes a previously undocumented Windows loader named TriBack Loader. The discovery stemmed from an exposed Alibaba Cloud server found in mid-April 2026, which contained forensic evidence of the group's activities.
The exposed server's data revealed active intrusions against a Vietnamese public hospital's medical imaging system and Malaysia's Ministry of Foreign Affairs. It also showed scanning and exploitation attempts against Hong Kong's education infrastructure and a spear-phishing package aimed at the National Congress of Honduras. The attackers gained access to the hospital's imaging server via webshells planted on an exposed Java management interface.
TriBack Loader is built around DLL sideloading, appearing in four distinct infection chains. Most variants combine a legitimate signed executable with a malicious DLL and an encrypted payload. The DLL decrypts and executes shellcode using Win32 calls like InitOnceExecuteOnce, TimerQueue callbacks, or the undocumented EtwpCreateEtwThread, which are less monitored by EDR solutions. The consistent API sequence suggests the use of a custom loader builder.
Two variants of TriBack Loader delivered AdaptixC2, an open-source post-exploitation framework. Another variant, themed around Claude AI, used DonutLoader to deploy the Beagle backdoor, previously documented by Sophos. Spear-phishing campaigns involved decoys such as fake beverage-company account statements and malicious MSI installers impersonating Anthropic's Claude software from a newly registered domain, claude-pro[.]com. This installer placed the sideloading chain in the Windows Startup folder for persistence.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Group-IB uncovered a China-nexus operation, JadeProx, that used a new Windows loader called TriBack Loader to target government, healthcare, and education organizations in Asia and Latin America. The discovery was made through an exposed Alibaba Cloud server, revealing active intrusions and spear-phishing campaigns. This new loader employs DLL sideloading and various evasion techniques, posing a threat to targeted sectors.