An exposed server on Alibaba Cloud has brought to light a China-linked operation identified as JadeProx by Group-IB. This campaign has aggressively targeted government, healthcare, and education sectors in Asia and Latin America using a new Windows malware loader named TriBack Loader.
Discovery of the JadeProx Operation
Group-IB discovered the compromised server in mid-April 2026, hosted in Alibaba Cloud’s Singapore region. By July 23, 2026, when the report was published, the server had been taken offline. An analysis of its bash history, phishing kits, and exploitation tools revealed ongoing attacks on entities such as a Vietnamese hospital’s imaging system and Malaysia’s foreign affairs ministry.
The attackers leveraged webshells on an exposed Java management interface to infiltrate the hospital’s imaging server. Further activities involved spear-phishing the National Congress of Honduras and probing Hong Kong’s educational infrastructure for vulnerabilities.
Technical Breakdown of TriBack Loader
TriBack Loader employs four different infection pathways, relying primarily on DLL sideloading techniques. Each build typically pairs a legitimate signed executable with a malicious DLL and an encrypted payload file. The DLL decrypts and executes the payload using methods that evade standard endpoint detection and response (EDR) systems.
The loader’s variants use different API calls for execution, suggesting the use of a custom loader builder. Some versions have been linked to delivering AdaptixC2, a known post-exploitation framework, while others have utilized the Beagle backdoor, previously documented by Sophos. A fourth variant’s payload is unknown due to the loss of its companion file.
Implications and Detection Strategies
JadeProx’s operation involved a large-scale scanning of Hong Kong educational URLs, uncovering multiple vulnerabilities. The group also attempted to exploit several critical CVEs, confirmed by The Hacker News, including flaws in ASUSTOR, WordPress, Tenda routers, and WebSVN, each with a high severity score.
Sophos identified a likely malvertising campaign linked to a fake Claude software site, suggesting a broader risk beyond immediate targets. Detection strategies should focus on monitoring file layouts and flagging abnormal activities such as vendor binaries running from non-standard directories or the presence of encrypted files in suspicious locations.
Organizations are advised to block or scrutinize domains associated with the operation and prioritize patching systems exposed to internet-facing vulnerabilities.
Conclusion
The JadeProx operation underscores the persistent threat posed by sophisticated cyber attackers leveraging both new and old vulnerabilities. The discovery of TriBack Loader highlights the need for vigilant cybersecurity practices, especially in sectors susceptible to such targeted attacks. Moving forward, enhancing detection capabilities and ensuring timely updates and patches on vulnerable systems remain critical in combating these threats.
