Home/News/JadeProx Uses TriBack Loader in Government, Healthcare Attacks
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

JadeProx Uses TriBack Loader in Government, Healthcare Attacks

JadeProx Uses TriBack Loader in Government, Healthcare Attacks

A China-nexus cyber-espionage operation, identified by Group-IB as JadeProx, has been observed deploying a novel Windows loader named TriBack Loader. This previously undocumented malware was discovered on an exposed Alibaba Cloud server located in the Singapore region in mid-April 2026. By the time of Group-IB's reporting, the server had been taken offline. JadeProx has specifically targeted government, healthcare, and educational organizations across Asia and Latin America. The group's modus operandi involves exploiting vulnerabilities and deploying sophisticated tools to gain persistent access to victim networks. The use of TriBack Loader signifies an evolution in JadeProx's toolkit, suggesting ongoing development and adaptation to evade detection. Group-IB's analysis indicates that the loader is designed to establish a foothold on compromised systems, likely for subsequent stages of data exfiltration or further network compromise. The targeting of critical sectors like government and healthcare highlights the potential impact of these operations on national security and public services. Further investigation into the specific capabilities of TriBack Loader and the broader objectives of JadeProx is ongoing, with Group-IB continuing to monitor the threat landscape for related activities. The discovery underscores the persistent threat posed by state-sponsored or state-affiliated hacking groups operating from China.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next