CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3106

As cited

Copy frozen at (site build).

threat intel

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Group-IB identified a China-linked threat actor designated JadeProx through an exposed Alibaba Cloud server in Singapore. The group deployed a previously unknown Windows loader called TriBack Loader in attacks against government, healthcare, and education organizations across Asia and Latin America.

Why it matters: Government and healthcare practitioners in Asia and Latin America face direct targeting by an active threat cluster; defenders should monitor for TriBack Loader artifacts and assess lateral movement risks in environments exposed to this campaign.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Group-IB identified a China-linked threat actor designated JadeProx through an exposed Alibaba Cloud server in Singapore. The group deployed a previously unknown Windows loader called TriBack Loader in attacks against government, healthcare, and education organizations across Asia and Latin America.

Why it matters: Government and healthcare practitioners in Asia and Latin America face direct targeting by an active threat cluster; defenders should monitor for TriBack Loader artifacts and assess lateral movement risks in environments exposed to this campaign.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary