Home / Jul 24, 2026 / Story
0
#8 The Hacker News general July 23, 2026 at 12:20 UTC

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

By [email protected] (The Hacker News)

AI Summary

Group-IB identified a China-nexus threat cluster tracked as JadeProx via an exposed Alibaba Cloud server in Singapore (discovered mid-April 2026) that was deploying a previously undocumented Windows loader called TriBack Loader against government, healthcare, and education targets across Asia and Latin America. The exposure of the Alibaba Cloud server provided rare visibility into the group's tooling and targeting patterns. Security teams in those sectors and regions should treat TriBack Loader indicators as high-priority threat intelligence.

Relevance score: 75.0/100

# More from July 24