Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

post, juli 23, 2026juli 27, 2026

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.

Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the time the report published on July 23, 2026.

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks: China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
geopolitics vulnerability 2026China

Bericht navigatie

Previous post
Next post

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes