China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware
ID: 86f0a8c6-14f9-53de-8c66-e86cc75c0be0
STIX ID: report--86f0a8c6-14f9-53de-8c66-e86cc75c0be0
Feed Name: ThreatCluster
A Group-IB discovery revealed a China-linked espionage campaign that deployed a new loader, TriBack Loader, to infiltrate a Vietnamese public hospital's imaging systems and multiple government entities across South-East Asia and Latin America. The attackers used DLL sideloading and Windows callback API targeting to evade endpoint security, ran phishing campaigns impersonating Anthropic's Claude AI, and left an exposed command server containing tools and scripts (including a modified fuckaliyun.sh) that detailed victim lists and operational tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
