Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware
ID: 64b7122c-2e38-5185-ab17-b83f19cb3956
STIX ID: report--64b7122c-2e38-5185-ab17-b83f19cb3956
Feed Name: cybersecurityNews.com
Group-IB researchers exposed a global espionage campaign tracked as JadeProx after operators left an Alibaba Cloud staging server openly accessible; the campaign uses a new loader called TriBack that leverages DLL sideloading and unconventional Windows callbacks to evade detection and deliver backdoors (AdaptixC2, Beagle) to targets including hospitals, government ministries, and education sites across Southeast Asia and Latin America, and the report includes detailed IoCs (IPs, domains, file hashes) and hunting/mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
