China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Summary

A China-nexus operation, tracked as JadeProx by Group-IB, has been observed targeting government, healthcare, and education organizations in Asia and Latin America. The group utilizes a new, undocumented Windows loader named TriBack Loader. The operation was discovered via an exposed Alibaba Cloud server.

IFF Assessment

FOE

The discovery of a new threat actor and their tools indicates an increased threat landscape for defenders.

Defender Context

Defenders should be aware of the JadeProx operation and its use of the TriBack Loader, particularly if their organizations operate in the government, healthcare, or education sectors in Asia or Latin America. Monitoring for suspicious activity related to new Windows loaders and the compromise of cloud infrastructure remains critical.

Read Full Story →