Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks

China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks

Posted on July 23, 2026 By CWS

An exposed server on Alibaba Cloud has brought to light a China-linked operation identified as JadeProx by Group-IB. This campaign has aggressively targeted government, healthcare, and education sectors in Asia and Latin America using a new Windows malware loader named TriBack Loader.

Discovery of the JadeProx Operation

Group-IB discovered the compromised server in mid-April 2026, hosted in Alibaba Cloud’s Singapore region. By July 23, 2026, when the report was published, the server had been taken offline. An analysis of its bash history, phishing kits, and exploitation tools revealed ongoing attacks on entities such as a Vietnamese hospital’s imaging system and Malaysia’s foreign affairs ministry.

The attackers leveraged webshells on an exposed Java management interface to infiltrate the hospital’s imaging server. Further activities involved spear-phishing the National Congress of Honduras and probing Hong Kong’s educational infrastructure for vulnerabilities.

Technical Breakdown of TriBack Loader

TriBack Loader employs four different infection pathways, relying primarily on DLL sideloading techniques. Each build typically pairs a legitimate signed executable with a malicious DLL and an encrypted payload file. The DLL decrypts and executes the payload using methods that evade standard endpoint detection and response (EDR) systems.

The loader’s variants use different API calls for execution, suggesting the use of a custom loader builder. Some versions have been linked to delivering AdaptixC2, a known post-exploitation framework, while others have utilized the Beagle backdoor, previously documented by Sophos. A fourth variant’s payload is unknown due to the loss of its companion file.

Implications and Detection Strategies

JadeProx’s operation involved a large-scale scanning of Hong Kong educational URLs, uncovering multiple vulnerabilities. The group also attempted to exploit several critical CVEs, confirmed by The Hacker News, including flaws in ASUSTOR, WordPress, Tenda routers, and WebSVN, each with a high severity score.

Sophos identified a likely malvertising campaign linked to a fake Claude software site, suggesting a broader risk beyond immediate targets. Detection strategies should focus on monitoring file layouts and flagging abnormal activities such as vendor binaries running from non-standard directories or the presence of encrypted files in suspicious locations.

Organizations are advised to block or scrutinize domains associated with the operation and prioritize patching systems exposed to internet-facing vulnerabilities.

Conclusion

The JadeProx operation underscores the persistent threat posed by sophisticated cyber attackers leveraging both new and old vulnerabilities. The discovery of TriBack Loader highlights the need for vigilant cybersecurity practices, especially in sectors susceptible to such targeted attacks. Moving forward, enhancing detection capabilities and ensuring timely updates and patches on vulnerable systems remain critical in combating these threats.

The Hacker News Tags:AdaptixC2, Beagle backdoor, China-nexus, cyber attacks, Cybersecurity, DLL Sideloading, government hacking, Group-IB, healthcare security, JadeProx, Malware, Sideloading, Sophos, spear-phishing, threat intelligence, TriBack Loader

Post navigation

Previous Post: Next.js Addresses Critical Security Vulnerabilities
Next Post: Hackers Exploit Notepad++ Plugins for Silent System Breach

Related Posts

New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login The Hacker News
Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents The Hacker News
Lazarus Group Targets Finance with RemotePE Malware Lazarus Group Targets Finance with RemotePE Malware The Hacker News
OpenAI Addresses Malicious Axios Incident in macOS Apps OpenAI Addresses Malicious Axios Incident in macOS Apps The Hacker News
React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors The Hacker News
AI Value in SOCs: What the Next Wave Must Offer AI Value in SOCs: What the Next Wave Must Offer The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark