Also known as: healthcare, JadeProx targeting government, Latin America, tracked as, JadeProx conducted espionage activity, an Iran-nexus threat group, education organizations across Asia, Southeast, Certighost, SkyCloak
Jadeprox first surfaced when analysts discovered a misconfigured Alibaba Cloud staging server that inadvertently exposed critical files such as bash command history, web shell paths, phishing kits, and tunneling utilities. The compromised host ran a Python HTTP service on port 8000 that served an eclectic mix of malware components: the TriBack Loader (a signed‐binary DLL sideloading mechanism), XMRig miner binaries, and various tunneling tools including iox, suo5, and Neo‑reGeorg. The group’s initial access vector is tri‑faceted. It leverages spearphishing that mimics fake Venezuelan tax portals or an Anthropic “Claude” download site, exploits high‑severity CVEs in publicly exposed web applications (e.g., Roundcube, JMX interfaces in PACS servers), and takes advantage of a cloud staging environment’s exposed directory listings. Once inside, TriBack performs DLL sideloading from trusted signed binaries such as hostfxr.exe or MpCopyAccelerator.pdb using uncommon Windows callbacks (InitOnceExecuteOnce, TimerQueue timers, undocumented EtwpCreateEtwThread) to avoid sandbox detection. After establishing footholds it deploys a multi‑layered C2 architecture: HTTPS traffic to custom backdoors, HTTP proxies relayed through Cloudflare, and an embedded XMRig miner that serves as either a crypto‑mining payload or a “dead‑drop” during idle periods. Persistence is achieved via startup folder entries created by MSI installers, scheduled tasks, registry Run keys, and obfuscated DLL injections into legitimate processes. Victim profiles span healthcare (Vietnam hospital imaging servers), ministries (Malaysia Foreign Ministry), educational institutions in Hong Kong, and public bodies in Honduras and Venezuela. The campaign demonstrates a state‑backed entity that combines publicly available exploitation tools with custom loaders to maintain stealth, persistence, and extended dwell times across multiple regions.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Jadeprox is an Iran‑linked APT that emerged in April 2026 through a misconfigured Alibaba Cloud staging server. It blends classic spearphishing and public vulnerability exploitation with a custom signed‑binary loader (TriBack Loader) to stealthily establish persistence, DLL sideloading, and encrypted C2 channels across healthcare, government, and education sectors worldwide. Its operations are rapid, multi‑vector, and highly sophisticated, employing cloud infrastructure abuse and cryptomining as evasive techniques while targeting data of strategic or financial value.
Goals & Targeting
Jadeprox seeks to harvest high‑value data from sectors that hold strategic or financial leverage—healthcare records, governmental documents, academic research, and critical infrastructure. While it claims a primary motive of financial gain through mining or ransomware, its operations exhibit characteristics of a state‑aligned APT capable of long‑term espionage. The actor’s strategy is to infiltrate high‑visibility institutions via low‑friction vectors (phishing, CVE exploitation) and embed covert persistence mechanisms that avoid conventional detection. The geographical spread—from Latin America to Southeast Asia—suggests an opportunistic reach into politically vulnerable regions. By exploiting cloud misconfigurations and leveraging legitimate infrastructure (Alibaba Cloud, Cloudflare), Jadeprox minimizes attribution risk while maximizing access opportunities. Ultimately, the actor’s objectives are two‑fold: extract sensitive information and monetize via cryptocurrency mining or potential blackmail, thereby creating financial pressure on targeted entities.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Jadeprox’s first documented engagement in April 2026 leveraged a compromised Alibaba Cloud staging environment to deliver a wide array of malware, including the TriBack Loader and custom backdoors. The actor combines phishing, public vulnerability exploitation, and cloud misconfiguration to gain initial foothold across a broad geographic footprint—Latin America, Southeast Asia, Eastern Europe, and North America. Operational tempo is high: within days of discovery multiple attacks spanned healthcare facilities in Vietnam, diplomatic ministries in Malaysia, educational institutions in Hong Kong, and public bodies in Honduras and Venezuela. Jadeprox uses a custom Go‑based proxy stack behind Cloudflare to obfuscate HTTP C2 traffic and deploys cryptomining as a decoy during idle periods. While no prior campaign of this scale has been documented, the actor’s methodology indicates a learned, mature threat group that blends conventional APT TTPs with opportunistic exploitation of misconfigured cloud infrastructure, thereby enabling rapid expansion into new targets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is of moderate confidence: multiple independent indicators—misconfigured cloud staging, observed malware samples, phishing domains, and exploitation of known CVEs—support the existence and capabilities of Jadeprox. However, precise attribution to a state actor remains uncertain, as does the full extent of its operational footprint and long‑term strategic objectives. Further evidence from internal telemetry or additional incident reports would increase confidence.
No campaigns linked yet.
No observed data linked yet.
19
Techniques
66
Tools
0
Campaigns
40
IOCs
0
Observed Data
8
Tactics