#8
The Hacker News
general
July 23, 2026 at 12:20 UTC
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
By [email protected] (The Hacker News)
AI Summary
Group-IB identified a China-nexus threat cluster tracked as JadeProx via an exposed Alibaba Cloud server in Singapore (discovered mid-April 2026) that was deploying a previously undocumented Windows loader called TriBack Loader against government, healthcare, and education targets across Asia and Latin America. The exposure of the Alibaba Cloud server provided rare visibility into the group's tooling and targeting patterns. Security teams in those sectors and regions should treat TriBack Loader indicators as high-priority threat intelligence.
Relevance score: 75.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →