China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Group-IB tracks a China-nexus operation known as JadeProx, which was disclosed by an Alibaba Cloud server. The network has used a previously unreported Windows loader known as TriBack Loader to target government, healthcare, and educational institutions in Asia and Latin America.
By the time the report was released on July 23, 2026, Group-IB had discovered the server in the Singapore area of Alibaba Cloud in mid-April 2026.
The operation was outlined by its bash history, phishing packages, post-exploitation tools, and webshell paths: active intrusions against the medical imaging system of a Vietnamese public hospital and Malaysia's Ministry of Foreign Affairs; scanning and exploitation follow-up against the education infrastructure in Hong Kong; and a spear-phishing package sent to ...

