As cited
Copy frozen at (site build).
threat intel
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Group-IB identified a China-linked threat actor designated JadeProx through an exposed Alibaba Cloud server in Singapore. The group deployed a previously unknown Windows loader called TriBack Loader in attacks against government, healthcare, and education organizations across Asia and Latin America.
Why it matters: Government and healthcare practitioners in Asia and Latin America face direct targeting by an active threat cluster; defenders should monitor for TriBack Loader artifacts and assess lateral movement risks in environments exposed to this campaign.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Group-IB identified a China-linked threat actor designated JadeProx through an exposed Alibaba Cloud server in Singapore. The group deployed a previously unknown Windows loader called TriBack Loader in attacks against government, healthcare, and education organizations across Asia and Latin America.
Why it matters: Government and healthcare practitioners in Asia and Latin America face direct targeting by an active threat cluster; defenders should monitor for TriBack Loader artifacts and assess lateral movement risks in environments exposed to this campaign.
- Source published
- First seen by Cybersecurity Tracker