← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

China-Nexus JadeProx Group Uses New TriBack Loader in Attacks on Government and Healthcare

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • JadeProx operation used TriBack Loader against government, healthcare, education.
  • Exposed Alibaba Cloud server revealed details of the attacks.
  • TriBack Loader utilizes DLL sideloading with evasion techniques.
  • Targets included Vietnam, Malaysia, Hong Kong, and Honduras.

Discovery of JadeProx Operation and TriBack Loader

Group-IB identified a China-nexus cyber operation, tracked as JadeProx, which has been targeting government, healthcare, and education sectors across Asia and Latin America. The operation utilizes a previously undocumented Windows loader named TriBack Loader. The discovery stemmed from an exposed Alibaba Cloud server found in mid-April 2026, which contained forensic evidence of the group's activities.

Targeted Organizations and Attack Vectors

The exposed server's data revealed active intrusions against a Vietnamese public hospital's medical imaging system and Malaysia's Ministry of Foreign Affairs. It also showed scanning and exploitation attempts against Hong Kong's education infrastructure and a spear-phishing package aimed at the National Congress of Honduras. The attackers gained access to the hospital's imaging server via webshells planted on an exposed Java management interface.

Technical Details of TriBack Loader

TriBack Loader is built around DLL sideloading, appearing in four distinct infection chains. Most variants combine a legitimate signed executable with a malicious DLL and an encrypted payload. The DLL decrypts and executes shellcode using Win32 calls like InitOnceExecuteOnce, TimerQueue callbacks, or the undocumented EtwpCreateEtwThread, which are less monitored by EDR solutions. The consistent API sequence suggests the use of a custom loader builder.

Payloads and Spear-Phishing Campaigns

Two variants of TriBack Loader delivered AdaptixC2, an open-source post-exploitation framework. Another variant, themed around Claude AI, used DonutLoader to deploy the Beagle backdoor, previously documented by Sophos. Spear-phishing campaigns involved decoys such as fake beverage-company account statements and malicious MSI installers impersonating Anthropic's Claude software from a newly registered domain, claude-pro[.]com. This installer placed the sideloading chain in the Windows Startup folder for persistence.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~39 min · 35 stories · Jul 22

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Group-IB uncovered a China-nexus operation, JadeProx, that used a new Windows loader called TriBack Loader to target government, healthcare, and education organizations in Asia and Latin America. The discovery was made through an exposed Alibaba Cloud server, revealing active intrusions and spear-phishing campaigns. This new loader employs DLL sideloading and various evasion techniques, posing a threat to targeted sectors.