logo

JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake

ID: 15d07d1f-9296-57d8-a1f9-3d2dcaa56746

STIX ID: report--15d07d1f-9296-57d8-a1f9-3d2dcaa56746

Feed Name: Group-IB Blog

Threat Score
88/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

...
...

Group-IB discovered an exposed Alibaba Cloud staging server revealing a multi-country China‑nexus operation dubbed "JadeProx" that used a custom TriBack Loader (DLL sideloading and Win32 callback APIs) to deploy AdaptixC2 and a novel Beagle backdoor via phishing lures and MSI/LNK installers; the report includes full infection chain analysis, four loader variants, extensive IOCs (domains, IPs, file hashes), victimology (Vietnam, Malaysia, Hong Kong, Honduras, Venezuela), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.