Skip to content
feed: live
>_ 0dayNews
threat intel

China-Linked JadeProx Deploys TriBack Loader in Gov Attacks

Group-IB exposes JadeProx: a China-nexus cluster deploying an undocumented Windows loader against gov, healthcare, and education targets in Asia and LATAM.

China-Linked JadeProx Deploys TriBack Loader in Gov Attacks
Image: 0dayNews / 0dayNews Editorial · All rights reserved
fuse Marisol "Fuse" Delgado · Published · 1 min read

Group-IB disclosed a China-nexus cluster it tracks as JadeProx on July 23, 2026, detailing a previously undocumented Windows loader called TriBack Loader used in campaigns against government, healthcare, and education organizations across Asia and Latin America. The tell: an exposed Alibaba Cloud server in Singapore’s region, discovered mid-April 2026, was already offline by the time Group-IB published — but what was on it was enough to profile the cluster and name its tooling.

The Hacker News coverage of Group-IB’s analysis has the full technical breakdown.

What we know

TriBack Loader is newly documented — Group-IB is the first to publish on it publicly. The targeting scope is government, healthcare, and education across Asia and Latin America. The Alibaba Cloud server in Singapore is the infrastructure artifact that surfaced the cluster.

The “China-nexus” label is Group-IB’s, based on technical indicators. No direct state attribution is asserted.

Who this matters to right now

Security teams in government, healthcare, or education with any Asia-Pacific or Latin American footprint should treat JadeProx as an active threat against their sector. TriBack Loader is new enough that detection coverage may lag — verify your endpoint tooling has signatures rather than assuming they’ll appear automatically.

Concrete steps

  1. Pull Group-IB indicators from the July 23 report and run them against endpoint telemetry, DNS query logs, and egress firewall logs.
  2. Flag anomalous outbound connections to Alibaba Cloud infrastructure in the Singapore region. The known server is offline; the cluster will have rotated, but the pattern still anchors hunt queries.
  3. Review initial-access hardening relevant to this profile: exposed management interfaces, phishing-resistant MFA, and lateral movement tripwires.
  4. If your EDR vendor has released TriBack Loader signatures, push them now. If not, ask explicitly — “newly documented” often means coverage is a week behind.

For related China-nexus tradecraft context, see HollowGraph’s M365 calendar-event C2 dead drop.

Found this useful? Share it.