logo

New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs

ID: 8673848b-b397-5d21-a3b9-165b518802ba

STIX ID: report--8673848b-b397-5d21-a3b9-165b518802ba

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

Author: Mayura Kathir

...
...

TriBack Loader is a custom shellcode loader used by the JadeProx cluster to conduct espionage across SEA and LATAM, employing DLL sideloading with signed binaries and uncommon Win32 callback APIs (e.g., InitOnceExecuteOnce, TimerQueue callbacks, EtwpCreateEtwThread) to evade EDR; investigators recovered an exposed Alibaba Cloud staging server containing post-exploitation toolkits, phishing lures, beacon configurations (AdaptixC2), Donut-based reflective loaders (Beagle backdoor), and multiple C2 domains and IOCs for defenders to hunt.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.