#jadeprox
-Clop targets PTC Windchill and FlexPLM servers
-New AfterCall adware
-New Dolphin X Stealer and msaRAT
-OpSec leak exposes JadeProx operations
-UAC-0099 distributes malicious Notepad++ plugins
-DPRK job interviews adopt ClickFix
-Lots of Kimsuky ops
-Review of the Iran cyber war landscape
July 24, 2026 at 8:02 AM
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
thehackernews.com
July 23, 2026 at 3:07 PM
Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware
Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware
A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents in early 2026. In mid April, operators left a staging server open with tools, command history, and phishing packages ready. That slip exposed an active campaign now tracked as JadeProx, centered on a newly identified loader called TriBack. The campaign hit a Vietnamese public hospital medical imaging system, the Malaysian Ministry of Foreign Affairs, and several Hong Kong education sites at once. Parallel activity also reached Honduras and used fake Claude software themes to lure victims into opening staged packages. Analysts from Group-IB identified the malware and mapped how the same loader appeared in every infection chain they reviewed. Group-IB said in a report  shared with Cyber Security News (CSN) that TriBack Loader starts through DLL sideloading. It decrypts and runs shellcode using everyday Windows callback functions so security tools are less likely to notice the launch. Two variants drop AdaptixC2 beacons, while another delivers a backdoor tracked as Beagle. Fake portals, including one posing as a Venezuelan municipal tax system, ran on campaign infrastructure to steal credentials from visitors. Targets stretched from South East Asia into Latin America, matching patterns often seen in China nexus spying. Honduras received a lure styled as a major local beverage company statement sent toward its National Congress. Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign The operators exposed their Alibaba Cloud staging box by leaving a Python web server with directory listing turned on. The host held bash history, webshell paths, phishing kits, and post exploitation tools in plain view. Attack Chain and Infrastructure (Source – Group-IB) Inside the open folder sat port forwarders, SOCKS tunnels, network scanners, and scripts meant to hide the server from cloud host monitoring. Command logs showed tunnels into the Vietnamese hospital imaging system and access attempts against Malaysian foreign affairs systems. Figure 2 maps the victim footprint spanning SEA and LATAM regions. Those same logs revealed how the actors served DLL sideloading packages to Windows hosts reached through internal tunnels. A related archive aimed at Honduras used a signed Microsoft host binary to load a malicious DLL without easy alerts. Claude themed packages abused other trusted vendor programs in a similar way across uploads. Teams tracking  DLL side loading methods  will recognize how trusted programs were twisted to start the next stage quietly. How TriBack Loader Evades Defenses TriBack Loader arrives as a small set of files, a signed program, a malicious DLL, and an encrypted data file. After a short decrypt step that reverses bytes and applies a rolling key, the code runs through unusual Windows callbacks instead of common thread starts. That design helps it slip past many endpoint products that watch for ordinary thread creation patterns on workstations. Four builds appeared across roughly two months, each swapping host binaries and callback choices while keeping the same builder style. Two of them delivered AdaptixC2 with full beacon settings recovered by researchers, including sleep times and HTTP profiles. JadeProx victimology map (Source – Group-IB) A third path used shellcode to run Beagle and talked to domains that followed the same registration pattern. Related coverage of  open source AdaptixC2 abuse  shows why this framework keeps attracting operators. Defenders should block listed domains and addresses at the edge and DNS layer. They should also hunt for nested folders named like underscore CL followed by digits in mail and endpoint logs. Flag signed vendor binaries that launch from user writable paths when a companion data or log file sits nearby. Review Startup folder entries, watch for a double extension cleanup script, and prioritize fixes for internet facing Java apps plus unpatched critical flaws. Broader  Chinese APT campaign activity  often shares loaders and tunnel tools, so TriBack keys remain strong hunting anchors. Guidance on  network hunting mitigation steps  can help teams apply these findings. Indicators of Compromise (IoCs):- Type Indicator Description IP Address 43.106.71[.]28:8000 Exposed operator staging server (Alibaba Cloud Singapore) IP Address 8.217.190[.]58 C2 related to license[.]claude-pro[.]com (Alibaba US) IP Address 104.21.60[.]96 Cloudflare IP for sylverixstrategy[.]com IP Address 161.35.236[.]255 DigitalOcean IP for gouvvbo[.]top IP Address 178.128.108[.]89 DigitalOcean IP for vertextrust-advisors[.]com IP Address 192.252.186[.]62 C2 for update-trellix[.]com and related update domains Domain sylverixstrategy[.]com AdaptixC2 C2 domain (open directory variant) Domain gouvvbo[.]top AdaptixC2 C2 domain (Honduras variant) Domain license[.]claude-pro[.]com Beagle / Claude-Pro themed variant C2 Domain claude-pro[.]com Phishing domain hosting MSI packages Domain vertextrust-advisors[.]com Fake advisory portal on campaign infrastructure Domain update-trellix[.]com C2 domain used with GolddTV.msi variant Domain update-crowdstrike[.]com Related NameSilo-registered update lure domain Domain update-sentinelone[.]com Related NameSilo-registered update lure domain Domain dlrz-web.oss-cn-beijing.aliyuncs[.]com Alibaba OSS bucket used for staged tools File Hash (MD5) bb5c88de9e04e6306260b9f3a4498933 Estado de Cuenta.zip (Honduras lure archive) File Hash (MD5) 35cdbf8a16da1245d574a0365cb87287 Estado de Cuenta.lnk File Hash (MD5) 0e6d22c2a81d29b1f9d8395d44e19e53 script.vbs File Hash (MD5) d99392248bdd7e351e63ead6733638ba hostfxr.dll File Hash (MD5) df1f03a2534480a4838f62339bcb90d8 hostfxr.dll File Hash (MD5) 7840f30b395fac347f85b38633c2d08d bjh.zip File Hash (MD5) 9e01bf0e28c86435cfb1afaef44238e9 ServiceHub.DataWarehouseHost.exe.log File Hash (MD5) 5222a31cf24f9f57ae3d1831f264a983 ServiceHub.DataWarehouseHost.exe.dat File Hash (MD5) fef1d3cb35129ad25d95e279565b9001 Related Windows payload hash File Hash (MD5) f2ce6fe8b52dfbacfee482a48f4ae972 Claude-Pro-Relay-Technical-Overview.zip File Hash (MD5) 38e317af0fc0efcc88265f243a264542 suo5-linux-amd64 File Hash (MD5) 5b75b00a4b4c32b6e213514e80500a65 Related Linux tool hash File Hash (MD5) 8002ab4d0cf7e1888ee72de0b9f4282c linux_amd64 (garbled NPS proxy) File Hash (MD5) 7c84e75817349adcdea9925b86f67670 iox File Hash (MD5) aedd185b76ccda8d65dbd26204cc0e9a fuckaliyun.sh File Hash (MD5) f360afe51b499a036c7be8c0ecc4dc89 neoreg.py File Hash (MD5) 39d4012e49f58092ec5cefed13dbbcfd Related toolkit hash File Hash (MD5) dtdee5a2cdd4ce6ccb2e9279c9e13e8bd15 nuclei File Hash (MD5) b8053bcd04ce9d7d19c7f36830a9f26b fscan / mail.log File Hash (MD5) 0482d6053f96e6bde0a92af25497f3c0 socks5-server File Name Estado de Cuenta.zip Honduras-themed phishing archive File Name hostfxr.dll Malicious DLL sideloaded by signed Microsoft host File Name avk.dll Malicious DLL sideloaded via G DATA binary File Name MpClient.dll Malicious DLL in DeviceSync variant File Name ~del.vbs.bat Self-delete double-extension cleanup artifact File Name Claude.msi / GolddTV.msi MSI installers delivering TriBack Loader Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure. The post Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware appeared first on Cyber Security News .
cybersecuritynews.com
July 23, 2026 at 3:37 PM
Chaosランサムウェアの新バックドア「msaRAT」、ChromeやEdgeブラウザを使ってC2通信をルーティング | Codebook|Security News

Cisco Talosによると、Chaosランサムウェアの直近の攻撃は、Eメールまたはボイスフィッシング(ビッシング)から始まり、続いてリモートマネージメント ...
codebook.machinarecord.com/threatreport...
Chaosランサムウェアの新バックドア「msaRAT」、ChromeやEdgeブラウザを使ってC2通信をルーティング | Codebook|Security News
Chaosランサムウェアの新バックドア「msaRAT」、ChromeやEdgeブラウザを使ってC2通信をルーティング|中国関連の脅威クラスターJadeProx、政府・医療部門への攻撃で新たなローダーTriBackを使用
codebook.machinarecord.com
July 25, 2026 at 12:17 PM
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
JadeProx uses the new TriBack Loader against government, healthcare, and education targets through DLL sideloading and a fake Claude installer.
thehackernews.com
July 30, 2026 at 6:12 PM
JadeProx: il cluster cinese che si è tradito da solo mentre colpiva ospedali, ministeri e università in Asia
il blog: insicurezzadigitale.com/jadeprox-il-...

#cybersecurity #apt #backdoor #cina #claude #groupib #infosec #jadeprox #tribackloader
July 28, 2026 at 7:31 AM
# **JadeProx: il cluster cinese che si è tradito da solo mentre colpiva ospedali, ministeri e università in Asia**

@informatica
Un server Alibaba Cloud lasciato esposto ha rivelato JadeProx, cluster China-nexus dietro intrusioni contro un ospedale vietnamita, il Ministero degli Esteri malese e […]
Original post on poliverso.org
poliverso.org
July 27, 2026 at 6:19 PM
JadeProxが暴かれる:TriBackローダーと中国系C2インフラの全貌

無防備なディレクトリがスパイ活動の実態を暴露 ある1台のサーバーで見過ごされた設定ミスが、中国系サイバースパイインフラの内部構造をそのまま露呈させる結果となりました。Group-IBのサイバーセキュリティ専門家は、公開状態になっていたディレクトリへのアクセスに成功し、コマンドログ、悪意あるバイナリ...
JadeProxが暴かれる:TriBackローダーと中国系C2インフラの全貌
無防備なディレクトリがスパイ活動の実態を暴露 ある1台のサーバーで見過ごされた設定ミスが、中国系サイバースパイインフラの内部構造をそのまま露呈させる結果となりました。Group-IBのサイバーセキュリティ専門家は、公開状態になっていたディレクトリへのアクセスに成功し、コマンドログ、悪意あるバイナリ
blackhatnews.tokyo
July 26, 2026 at 1:52 PM
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
July 24, 2026 at 11:59 PM
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
www.group-ib.com
July 24, 2026 at 7:24 AM
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and La…
#hackernews #news
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report
thehackernews.com
July 24, 2026 at 10:33 AM
OPSEC failure reveals JadeProx campaign using TriBack malware to target global institutions. #CyberSecurity #Malware #TriBack #JadeProx #OPSEC #DataBreach #InfoSec thedailytechfeed.com/hackers-opse...
July 23, 2026 at 4:38 PM
JadeProx targets government and healthcare with TriBack Loader malware—but the real story is how they're getting in: decade-old unpatched vulnerabilities paired with custom DLL sideloading that bypasses standard EDR detection. #infosec #cybersecurity
JadeProx Targets Government and Healthcare with TriBack Loader Malware
JadeProx targets government and healthcare with TriBack Loader malware—but the real story is how they're getting in: decade-old unpatched vulnerabilities paired with custom DLL sideloading that bypasses standard EDR detection. #infosec #cybersecurity
captechgroup.com
July 23, 2026 at 6:10 PM
JadeProx: Tracing A China-Nexus Operation Through An OPSEC Mistake https://packetstorm.news/news/view/42471 #news
July 23, 2026 at 4:26 PM
JadeProx targets Asia and Latin America sectors with new TriBack Loader malware. #CyberSecurity #JadeProx #TriBackLoader #Malware #Asia #LatinAmerica #ThreatIntelligence thedailytechfeed.com/jadeprox-dep...
July 23, 2026 at 12:35 PM
A JadeProx China-nexus intrusion used TriBack Loader to compromise government, healthcare, and education targets across Asia and Latin America via webshells and DLL sideloading.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
July 23, 2026 at 3:05 PM
JadeProx hides in signed binaries - sideloaded DLLs run shellcode straight past EDR hooks. https://intel.threadlinqs.com/threat/TL-2026-1653 #ThreatIntel #CVE_2018_11511 #CVE_2021_24139 #TriBack
July 23, 2026 at 8:44 AM
JadeProx Exposed: How a Hidden Cyber Espionage Machine Revealed Its Global Attack Blueprint + Video

Introduction: The Accidental Leak That Exposed a Sophisticated Threat Network Cybercriminal and espionage operations often depend on secrecy, carefully hidden infrastructure, and controlled…
JadeProx Exposed: How a Hidden Cyber Espionage Machine Revealed Its Global Attack Blueprint + Video
Introduction: The Accidental Leak That Exposed a Sophisticated Threat Network Cybercriminal and espionage operations often depend on secrecy, carefully hidden infrastructure, and controlled communication channels. However, one operational mistake can reveal years of preparation. In the case of the JadeProx intrusion set, an exposed directory on an attacker-controlled Alibaba Cloud server provided researchers with an unprecedented look into the group’s internal operations, tools, targets, and post-exploitation techniques.
undercodenews.com
July 23, 2026 at 11:47 AM