Security · 5h ago
China-Linked JadeProx Deploys New TriBack Loader in Targeted Attacks
Group-IB uncovered a China-nexus threat group, JadeProx, using a new Windows loader called TriBack to target government, healthcare, and education organizations in Asia and Latin America. The loader was discovered on an exposed Alibaba Cloud server in Singapore in April 2026, which was taken offline before the report. The campaign highlights ongoing cyberespionage efforts by China-linked actors against critical sectors.
Meridian48 take
The discovery underscores the persistent threat from state-aligned groups, but the quick takedown suggests operational security gaps on the attacker's part.
Read the full reporting
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks →
The Hacker News
cyberespionagetriback-loader