Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
2 weeks ago

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

By info@thehackernews.com (The Hacker News)

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.