Group IB Uncovers JadeProx Campaign Using TriBack Loader To Target Government And Healthcare Networks

Group IB Uncovers JadeProx Campaign Using TriBack Loader To Target Government And Healthcare Networks

Cybersecurity researchers at Group IB have uncovered a China nexus cyber operation tracked as JadeProx after discovering an exposed Alibaba Cloud server that revealed details of ongoing attacks targeting government, healthcare, and education organizations across Asia and Latin America. The investigation identified a previously undocumented Windows malware component named TriBack Loader, which was used as part of multiple intrusion campaigns. According to Group IB, the exposed server was located in Alibaba Cloud’s Singapore region and was discovered in mid April 2026 before going offline by the time the company’s report was published on July 23, 2026. Analysis of the server’s contents, including bash history, phishing materials, post exploitation tools, and webshell locations, provided insight into active operations involving a Vietnamese public hospital, Malaysia’s Ministry of Foreign Affairs, education related infrastructure in Hong Kong, and a spear phishing campaign directed at the National Congress of Honduras.

Researchers found that the operators gained access to the Vietnamese hospital’s medical imaging system through webshells installed on an exposed Java management interface. Group IB identified four separate infection chains built around the TriBack Loader using DLL sideloading techniques. In most cases, attackers combined a legitimate digitally signed executable with a malicious DLL and an encrypted DAT or LOG payload. The malicious DLL reversed the encrypted payload bytes, decrypted them using a rolling XOR key, and executed shellcode through Windows API functions that attract less attention from endpoint detection and response tools than commonly monitored methods such as CreateThread. Different malware variants relied on execution methods including InitOnceExecuteOnce, TimerQueue callbacks, and the undocumented EtwpCreateEtwThread function in ntdll, while also changing the legitimate host executable used in each campaign. Researchers believe the recurring API patterns indicate the use of a custom malware builder. Two variants deployed the open source AdaptixC2 post exploitation framework, while another distributed the Beagle backdoor using DonutLoader through a campaign impersonating Anthropic Claude software. A fourth malware variant was identified, although its encrypted payload could not be recovered for further analysis.

The investigation also uncovered multiple phishing campaigns used to distribute the malware. One phishing archive contained a fake beverage company account statement, while another campaign impersonated Anthropic Claude using the domain claude pro.com, which was registered on March 28, 2026. Victims downloading a malicious MSI installer were prompted by User Account Control before the installer established persistence by placing the sideloading components into the Windows Startup folder. The installed Beagle backdoor then communicated with the command and control domain license.claude pro.com. Sophos independently analyzed the fake Claude infrastructure and malware samples, identifying a reused XOR encryption key in malware dating back to February 2026. However, the company noted that the shared encryption key alone was not sufficient to attribute the activity to a single threat actor. Group IB, using evidence recovered from the exposed server, associated these malware samples with the broader JadeProx operation but also stated that shared tools within the China nexus threat landscape make definitive attribution difficult because multiple groups frequently reuse the same malware and infrastructure.

Beyond malware deployment, the attackers conducted extensive reconnaissance and vulnerability scanning against internet facing systems. Researchers observed the operators using Nuclei with only critical severity templates against 14,653 education related URLs in Hong Kong, identifying 13 unique vulnerabilities for potential follow up activity. The report specifically referenced attempts to exploit CVE 2018 11511 affecting ASUSTOR ADM, CVE 2021 24139 in the 10Web Photo Gallery WordPress plugin, CVE 2021 31755 impacting Tenda AC11 routers, and CVE 2021 32305 affecting WebSVN, all carrying CVSS scores of 9.8. Group IB advised organizations to monitor for signed applications executing from user writable, temporary, or Startup directories alongside encrypted DAT or LOG files, as well as suspicious copies of hostfxr.dll, avk.dll, MpClient.dll, nested temporary folders, and batch scripts associated with the malware. Researchers also recommended blocking domains and infrastructure linked to the operation, prioritizing the security of internet facing Java applications, and ensuring that publicly accessible systems are updated against critical vulnerabilities. The report noted that while TriBack Loader demonstrates advanced malware engineering, the attackers still relied on exploiting security flaws first disclosed in 2018 and 2021 to gain initial access before deploying their custom tools.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Post Comment