New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs
ID: 8673848b-b397-5d21-a3b9-165b518802ba
STIX ID: report--8673848b-b397-5d21-a3b9-165b518802ba
Feed Name: GBHackers
TriBack Loader is a custom shellcode loader used by the JadeProx cluster to conduct espionage across SEA and LATAM, employing DLL sideloading with signed binaries and uncommon Win32 callback APIs (e.g., InitOnceExecuteOnce, TimerQueue callbacks, EtwpCreateEtwThread) to evade EDR; investigators recovered an exposed Alibaba Cloud staging server containing post-exploitation toolkits, phishing lures, beacon configurations (AdaptixC2), Donut-based reflective loaders (Beagle backdoor), and multiple C2 domains and IOCs for defenders to hunt.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
