logo

Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware

ID: 64b7122c-2e38-5185-ab17-b83f19cb3956

STIX ID: report--64b7122c-2e38-5185-ab17-b83f19cb3956

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

Author: Tushar Subhra Dutta

...
...

Group-IB researchers exposed a global espionage campaign tracked as JadeProx after operators left an Alibaba Cloud staging server openly accessible; the campaign uses a new loader called TriBack that leverages DLL sideloading and unconventional Windows callbacks to evade detection and deliver backdoors (AdaptixC2, Beagle) to targets including hospitals, government ministries, and education sites across Southeast Asia and Latin America, and the report includes detailed IoCs (IPs, domains, file hashes) and hunting/mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.