China-Nexus JadeProx Leverages TriBack Loader in Targeted Cyberattacks on Government and Healthcare Sectors
China-Nexus JadeProx employs a novel TriBack Loader malware to conduct targeted cyberattacks on government, healthcare, and education institutions across Asia and Latin America. The attack chain utilizes DLL sideloading techniques with signed executables, exploits known vulnerabilities (including CVE-2021-32305 and others with CVSS 9.8 scores), and includes phishing campaigns impersonating Claude and other services.
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.
Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report
*** END OF TRANSMISSION ***