CyberSecurity News
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
AI summary
A China-linked operation, tracked as JadeProx, has been uncovered through an exposed server on Alibaba Cloud. The operation has targeted organizations in the government, healthcare, and education sectors across Asia and Latin America. A previously undocumented Windows loader, known as TriBack Loader, is being used in these attacks. The exposed server, which was located in Alibaba Cloud's Singapore region, was discovered by Group-IB in mid-April 2026, but was offline by the time the report was made. The JadeProx cluster's activities have been observed targeting various sectors, indicating a broad scope of attack. Group-IB's findings have shed light on the tactics and tools used by this China-nexus operation.
Countries in focus
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

