Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks

China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks

Posted on July 23, 2026 By CWS

An exposed server on Alibaba Cloud has brought to light a China-linked operation identified as JadeProx by Group-IB. This campaign has aggressively targeted government, healthcare, and education sectors in Asia and Latin America using a new Windows malware loader named TriBack Loader.

Discovery of the JadeProx Operation

Group-IB discovered the compromised server in mid-April 2026, hosted in Alibaba Cloud’s Singapore region. By July 23, 2026, when the report was published, the server had been taken offline. An analysis of its bash history, phishing kits, and exploitation tools revealed ongoing attacks on entities such as a Vietnamese hospital’s imaging system and Malaysia’s foreign affairs ministry.

The attackers leveraged webshells on an exposed Java management interface to infiltrate the hospital’s imaging server. Further activities involved spear-phishing the National Congress of Honduras and probing Hong Kong’s educational infrastructure for vulnerabilities.

Technical Breakdown of TriBack Loader

TriBack Loader employs four different infection pathways, relying primarily on DLL sideloading techniques. Each build typically pairs a legitimate signed executable with a malicious DLL and an encrypted payload file. The DLL decrypts and executes the payload using methods that evade standard endpoint detection and response (EDR) systems.

The loader’s variants use different API calls for execution, suggesting the use of a custom loader builder. Some versions have been linked to delivering AdaptixC2, a known post-exploitation framework, while others have utilized the Beagle backdoor, previously documented by Sophos. A fourth variant’s payload is unknown due to the loss of its companion file.

Implications and Detection Strategies

JadeProx’s operation involved a large-scale scanning of Hong Kong educational URLs, uncovering multiple vulnerabilities. The group also attempted to exploit several critical CVEs, confirmed by The Hacker News, including flaws in ASUSTOR, WordPress, Tenda routers, and WebSVN, each with a high severity score.

Sophos identified a likely malvertising campaign linked to a fake Claude software site, suggesting a broader risk beyond immediate targets. Detection strategies should focus on monitoring file layouts and flagging abnormal activities such as vendor binaries running from non-standard directories or the presence of encrypted files in suspicious locations.

Organizations are advised to block or scrutinize domains associated with the operation and prioritize patching systems exposed to internet-facing vulnerabilities.

Conclusion

The JadeProx operation underscores the persistent threat posed by sophisticated cyber attackers leveraging both new and old vulnerabilities. The discovery of TriBack Loader highlights the need for vigilant cybersecurity practices, especially in sectors susceptible to such targeted attacks. Moving forward, enhancing detection capabilities and ensuring timely updates and patches on vulnerable systems remain critical in combating these threats.

The Hacker News Tags:AdaptixC2, Beagle backdoor, China-nexus, cyber attacks, Cybersecurity, DLL Sideloading, government hacking, Group-IB, healthcare security, JadeProx, Malware, Sideloading, Sophos, spear-phishing, threat intelligence, TriBack Loader

Post navigation

Previous Post: Next.js Addresses Critical Security Vulnerabilities
Next Post: Hackers Exploit Notepad++ Plugins for Silent System Breach

Related Posts

Malicious npm Package Targets Claude AI User Data Malicious npm Package Targets Claude AI User Data The Hacker News
Salesforce Flags Unauthorized Data Access via Gainsight-Linked OAuth Activity Salesforce Flags Unauthorized Data Access via Gainsight-Linked OAuth Activity The Hacker News
APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine The Hacker News
EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware The Hacker News
Think Your IdP or CASB Covers Shadow IT? These 5 Risks Prove Otherwise Think Your IdP or CASB Covers Shadow IT? These 5 Risks Prove Otherwise The Hacker News
US Leads in Global Phishing Scheme Targeting 46 Nations US Leads in Global Phishing Scheme Targeting 46 Nations The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark