logo

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

ID: cc60d135-c04d-520c-8a62-e92af57ef696

STIX ID: report--cc60d135-c04d-520c-8a62-e92af57ef696

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Group-IB exposed an Alibaba Cloud server revealing a China-nexus operation (tracked as JadeProx) that used a new Windows loader called TriBack Loader and multiple DLL sideloading builds to deliver post-exploitation tools and backdoors against government, healthcare, and education organizations across Asia and Latin America; the report includes detailed TTPs (phishing, malvertising, large-scale Nuclei scanning), high-severity CVEs targeted, and observable IOCs (domains, IP 43.106.71.28:8000, file patterns) for detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.