mimile
mimile.ai
Back to feed
This event is part of a larger story
Хакер развернул ИИ-агента без контроля при взломе Минфина Таиланда
Read briefing

China-linked JadeProx deploys TriBack Loader in Asia, Latin America attacks

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

China-linked JadeProx deploys TriBack Loader in Asia, Latin America attacks

Group-IB uncovered a China-nexus operation tracked as JadeProx targeting government, healthcare, and education organizations across Asia and Latin America with a new Windows loader called TriBack Loader. The cluster compromised a Vietnamese hospital's medical imaging system and Malaysia's Ministry of Foreign Affairs, among others. The findings were published July 23, 2026, based on an exposed Alibaba Cloud server discovered in April.

The Exposed Server

Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report published on July 23, 2026. Its bash history, phishing packages, post-exploitation tools, and webshell paths revealed active intrusions against a Vietnamese public hospital's medical imaging system and Malaysia's Ministry of Foreign Affairs. The operators also scanned and exploited Hong Kong education infrastructure and prepared a spear-phishing package addressed to the National Congress of Honduras.

TriBack Loader Variants

TriBack Loader appears in four infection chains built around DLL sideloading. Most recovered builds pair a legitimate signed executable with a malicious DLL and an encrypted .dat or .log payload. The DLL reverses the payload bytes, XORs them with a rolling key, and executes the shellcode through Win32 calls such as InitOnceExecuteOnce, a TimerQueue callback, or EtwpCreateEtwThread, an undocumented ntdll routine. Two variants delivered AdaptixC2, an open-source post-exploitation framework; a Claude-themed variant used DonutLoader to run the Beagle backdoor.

Attribution Challenges

Sophos found the same reused XOR key in builds going back to February but said a shared key was not enough to conclude one actor. Group-IB groups those builds with the Asian intrusions but stops short of naming an established group, noting that tooling moves freely in the China-nexus ecosystem. The operators also ran Nuclei with critical-severity templates against 14,653 Hong Kong education-related URLs, surfacing 13 unique vulnerabilities.

What's Next

The exposed server is now offline, but the operators may have shifted infrastructure. It remains unclear whether the TriBack Loader will be adopted by other China-nexus groups or if the current campaigns have been fully disrupted.

1 source

China-linked JadeProx deploys TriBack Loader in Asia, Latin America attacks