China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Read full story on The Hacker News
Share
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
AI disclosure

Summary

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.