China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Summary
A China-nexus operation, tracked as JadeProx by Group-IB, has been observed targeting government, healthcare, and education organizations in Asia and Latin America. The group utilizes a new, undocumented Windows loader named TriBack Loader. The operation was discovered via an exposed Alibaba Cloud server.
IFF Assessment
FOE
The discovery of a new threat actor and their tools indicates an increased threat landscape for defenders.
Defender Context
Defenders should be aware of the JadeProx operation and its use of the TriBack Loader, particularly if their organizations operate in the government, healthcare, or education sectors in Asia or Latin America. Monitoring for suspicious activity related to new Windows loaders and the compromise of cloud infrastructure remains critical.