logo

China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware

ID: 86f0a8c6-14f9-53de-8c66-e86cc75c0be0

STIX ID: report--86f0a8c6-14f9-53de-8c66-e86cc75c0be0

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

...
...

A Group-IB discovery revealed a China-linked espionage campaign that deployed a new loader, TriBack Loader, to infiltrate a Vietnamese public hospital's imaging systems and multiple government entities across South-East Asia and Latin America. The attackers used DLL sideloading and Windows callback API targeting to evade endpoint security, ran phishing campaigns impersonating Anthropic's Claude AI, and left an exposed command server containing tools and scripts (including a modified fuckaliyun.sh) that detailed victim lists and operational tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.