Back to Intel

Intel Node

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

lowadvisory2026-07-23T12:20:23+00:00source excerpt
malwarewindowscloud

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.

Read Original Source