HackerFeeds

CyberSecurity News

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

The Hacker News
· July 23, 2026

AI summary

A China-linked operation, tracked as JadeProx, has been uncovered through an exposed server on Alibaba Cloud. The operation has targeted organizations in the government, healthcare, and education sectors across Asia and Latin America. A previously undocumented Windows loader, known as TriBack Loader, is being used in these attacks. The exposed server, which was located in Alibaba Cloud's Singapore region, was discovered by Group-IB in mid-April 2026, but was offline by the time the report was made. The JadeProx cluster's activities have been observed targeting various sectors, indicating a broad scope of attack. Group-IB's findings have shed light on the tactics and tools used by this China-nexus operation.

Countries in focus

Read the full article at The Hacker Newsthehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.