Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors jadeprox

Also known as: healthcare, JadeProx targeting government, Latin America, tracked as, JadeProx conducted espionage activity, an Iran-nexus threat group, education organizations across Asia, Southeast, Certighost, SkyCloak

Description

Jadeprox first surfaced when analysts discovered a misconfigured Alibaba Cloud staging server that inadvertently exposed critical files such as bash command history, web shell paths, phishing kits, and tunneling utilities. The compromised host ran a Python HTTP service on port 8000 that served an eclectic mix of malware components: the TriBack Loader (a signed‐binary DLL sideloading mechanism), XMRig miner binaries, and various tunneling tools including iox, suo5, and Neo‑reGeorg. The group’s initial access vector is tri‑faceted. It leverages spearphishing that mimics fake Venezuelan tax portals or an Anthropic “Claude” download site, exploits high‑severity CVEs in publicly exposed web applications (e.g., Roundcube, JMX interfaces in PACS servers), and takes advantage of a cloud staging environment’s exposed directory listings. Once inside, TriBack performs DLL sideloading from trusted signed binaries such as hostfxr.exe or MpCopyAccelerator.pdb using uncommon Windows callbacks (InitOnceExecuteOnce, TimerQueue timers, undocumented EtwpCreateEtwThread) to avoid sandbox detection. After establishing footholds it deploys a multi‑layered C2 architecture: HTTPS traffic to custom backdoors, HTTP proxies relayed through Cloudflare, and an embedded XMRig miner that serves as either a crypto‑mining payload or a “dead‑drop” during idle periods. Persistence is achieved via startup folder entries created by MSI installers, scheduled tasks, registry Run keys, and obfuscated DLL injections into legitimate processes. Victim profiles span healthcare (Vietnam hospital imaging servers), ministries (Malaysia Foreign Ministry), educational institutions in Hong Kong, and public bodies in Honduras and Venezuela. The campaign demonstrates a state‑backed entity that combines publicly available exploitation tools with custom loaders to maintain stealth, persistence, and extended dwell times across multiple regions.

Goals & Targeting

Targeted Sectors

Healthcare
Government
Education
Financial services
Defense
Energy
Telecommunications
Critical infrastructure
Utilities
Hospitality
Pharmaceutical
Media
Mining
Manufacturing
Aviation
Retail
Gaming
Non profit
Nuclear
Transportation
Maritime
Aerospace
Construction

Targeted Countries / Regions

CN
IR
UA
SG
PL
IN
VN
US
JP
CA
GB
KP
KR
RO
RU
AU
TR
AZ
SA
ES
MX
FR
IT
TW
BR

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 4 hours ago

Executive Summary

Jadeprox is an Iran‑linked APT that emerged in April 2026 through a misconfigured Alibaba Cloud staging server. It blends classic spearphishing and public vulnerability exploitation with a custom signed‑binary loader (TriBack Loader) to stealthily establish persistence, DLL sideloading, and encrypted C2 channels across healthcare, government, and education sectors worldwide. Its operations are rapid, multi‑vector, and highly sophisticated, employing cloud infrastructure abuse and cryptomining as evasive techniques while targeting data of strategic or financial value.

Goals & Targeting

Jadeprox seeks to harvest high‑value data from sectors that hold strategic or financial leverage—healthcare records, governmental documents, academic research, and critical infrastructure. While it claims a primary motive of financial gain through mining or ransomware, its operations exhibit characteristics of a state‑aligned APT capable of long‑term espionage. The actor’s strategy is to infiltrate high‑visibility institutions via low‑friction vectors (phishing, CVE exploitation) and embed covert persistence mechanisms that avoid conventional detection. The geographical spread—from Latin America to Southeast Asia—suggests an opportunistic reach into politically vulnerable regions. By exploiting cloud misconfigurations and leveraging legitimate infrastructure (Alibaba Cloud, Cloudflare), Jadeprox minimizes attribution risk while maximizing access opportunities. Ultimately, the actor’s objectives are two‑fold: extract sensitive information and monetize via cryptocurrency mining or potential blackmail, thereby creating financial pressure on targeted entities.

Enhanced Description

Key Capabilities

  • Deploys webshells and staged phishing packages
  • Uses signed binary loader (TriBack Loader) for DLL sideloading and shellcode decryption
  • Exploits publicly facing vulnerabilities such as SQL injection, buffer overflow, arbitrary command execution
  • Harvest credentials through fake portals (tax systems, AI sites)
  • Spearfishing attachments (LNK, ZIP+PDF)
  • Delivers XOR‑encrypted Windows loader
  • Persistence via startup folder autostart & registry Run keys
  • DLL sideloading through signed legitimate binaries and masquerading file names
  • Obfuscates payloads with nested directories and encrypted files
  • Self‑deletes malware using batch scripts
  • Deploys custom Go‑based proxy infrastructure behind Alibaba/Cloudflare
  • Command and Control over HTTP with internal proxies (iox, suo5, Neo‑reGeorg)
  • Installs custom backdoors like BugSleep, StealthCache, Phoenix, Fooder loader
  • Uses malicious PowerShell scripts
  • Exploits publicly disclosed CVEs in unpatched systems
  • Evasion via signed binary proxy execution

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Credential Access
Reconnaissance
Resource Development
Persistence
Defense Evasion
Command and Control

ATT&CK Techniques

T1190
T1059.005
T1064
T1574.001
T1566.001
T1204.002
T1547.001
T1036.005
T1140
T1218
T1027
T1070.004
T1071.001
T1090.001
T1573.001

Software / Tooling

TriBack Loader
AdaptixC2
Beagle
PlugX
ClaimLoader
Neo-reGeorg
suo5
iox
fscan
Go-proxy
Nuclei
BugSleep
StealthCache
Phoenix
Fooder loader

Campaigns & Victims

Jadeprox’s first documented engagement in April 2026 leveraged a compromised Alibaba Cloud staging environment to deliver a wide array of malware, including the TriBack Loader and custom backdoors. The actor combines phishing, public vulnerability exploitation, and cloud misconfiguration to gain initial foothold across a broad geographic footprint—Latin America, Southeast Asia, Eastern Europe, and North America. Operational tempo is high: within days of discovery multiple attacks spanned healthcare facilities in Vietnam, diplomatic ministries in Malaysia, educational institutions in Hong Kong, and public bodies in Honduras and Venezuela. Jadeprox uses a custom Go‑based proxy stack behind Cloudflare to obfuscate HTTP C2 traffic and deploys cryptomining as a decoy during idle periods. While no prior campaign of this scale has been documented, the actor’s methodology indicates a learned, mature threat group that blends conventional APT TTPs with opportunistic exploitation of misconfigured cloud infrastructure, thereby enabling rapid expansion into new targets.

IOC Patterns

  • Exposed Alibaba Cloud directories without authentication
  • Signed malware binaries masquerading as legitimate DLLs (hostfxr.dll, avk.dll)
  • Phishing domains impersonating tax or AI services
  • Recently registered malicious domains with short TTLs
  • CVE exploitation of public web applications (e.g., CVE‑2018‑11511, CVE‑2021‑24139)
  • Obfuscated nested paths containing encrypted payloads
  • Encrypted/XOR‑encoded binaries and scripts
  • Self‑deleting batch scripts
  • Masquerading file names to avoid detection
  • Use of Go‑based proxies behind Cloudflare

Recommended Actions

  • Patch known CVEs promptly (e.g., SQLi, buffer overflow, command execution vulnerabilities)
  • Monitor cloud environments for exposed directories and unauthorized configuration changes
  • Deploy EDR/UEBA capable of detecting DLL sideloading via signed binaries and anomalous backdoor activity
  • Educate users on spearphishing attachments such as LNK, ZIP+PDF, and malicious PDFs
  • Block traffic to newly registered or suspicious domains using reputable threat feeds
  • Implement email filtering rules and user awareness programs to mitigate phishing attacks
  • Audit startup folders and registry Run keys for unauthorized persistence mechanisms
  • Detect obfuscated file paths, encrypted payloads, and self‑deleting scripts through sandboxing or behavioral analytics
  • Inspect outbound HTTP/S traffic for internal proxy patterns (iox, suo5, Neo‑reGeorg) and encrypted C2 channels
  • Harden cloud infrastructure access controls, especially on Alibaba Cloud instances, with least privilege and MFA
  • Monitor healthcare, government, education facilities for signs of compromise or anomalous activity

Suggested Tags

Jadeprox
TriBack Loader
Phishing
Credential Harvesting
Webshell
DLL Sideloading
SQL Injection
Public-Facing Application Exploitation
APT
Spearphishing Attachment
Masquerading
Obfuscation
Command and Control HTTP
Internal Proxy
Go-Proxy
Signed Binary Abuse
Cloud Exploitation
Alibaba Cloud
Cloudflare Domain

Confidence Assessment

The assessment is of moderate confidence: multiple independent indicators—misconfigured cloud staging, observed malware samples, phishing domains, and exploitation of known CVEs—support the existence and capabilities of Jadeprox. However, precise attribution to a state actor remains uncertain, as does the full extent of its operational footprint and long‑term strategic objectives. Further evidence from internal telemetry or additional incident reports would increase confidence.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 10 Domain 2 IPv4 Address 7 SHA-256 Hash 1

References

  1. https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader/ — Cited by AI analysis.
  2. https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html — Cited by AI analysis.
  3. https://x.com/hashtag/JadeProx?src=hashtag_click — Cited by AI analysis.
  4. https://www.techines.com/articles/jadeprox-tri-back-loader-attacks — Cited by AI analysis.
  5. https://www.sec-news.ai/news/jadeprox-operation-unveiled-targeting-government-and-healthcare-sectors-with-triback-loader — Cited by AI analysis.
  6. mallory.ai — Cited by web research for: Latin America
  7. www.group-ib.com — Cited by web research for: an Iran-nexus threat group
  8. thehackernews.com — Cited by web research for: Certighost
  9. www.gblock.app — Cited by web research for: T1574.002
  10. www.varutra.com — Cited by web research for: Spear-phishing
  11. www.techtimes.com — Cited by web research for: Singapore

Intel Summary

19

Techniques

66

Tools

0

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

China-nexus
Webshell Deployment
TriBack Loader
Alibaba Cloud misconfiguration
State-sponsored Espionage
Government Targets
Healthcare Targets
Education Targets
Phishing Attack
DLL Sideloading
Signed Binary Evasion
Proxy/Tunneling
Cryptocurrency Mining
XMRig Miner
Cloudflare Fronting
Jadeprox
Phishing
Credential Harvesting
Webshell
SQL Injection
Public-Facing Application Exploitation
APT
Spearphishing Attachment
Masquerading
Obfuscation
Command and Control HTTP
Internal Proxy
Go-Proxy
Signed Binary Abuse
Cloud Exploitation
Alibaba Cloud
Cloudflare Domain

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.