news.mlab.sh
Back to the feed
threat-intel

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

High
Summary

A China-nexus operation, tracked by Group-IB, dubbed JadeProx, is using a new loader called TriBack Loader to target government, healthcare, and education organizations across Asia and Latin America. The operation leverages a fake Claude website to deliver a spear-phishing campaign and exploits vulnerabilities in various products, including ASUSTOR ADM, 10Web Photo Gallery, Tenda routers, and WebSVN. Sophos identified a malvertising campaign linked to the operation, and recommends specific detection methods based on file layout and loader behavior.

A China-nexus operation, Group-IB’s JadeProx, is utilizing a new Windows loader, TriBack Loader, to conduct targeted attacks against government, healthcare, and education organizations in Asia and Latin America. The operation began in mid-April 2026 and has been active since July 23, 2026, according to Group-IB’s report.

What happened

The operation began with an exposed Alibaba Cloud server in Singapore, which served as a staging ground for the attacks. The server contained phishing packages, post-exploitation tools, and webshells, facilitating intrusions against a Vietnamese public hospital’s medical imaging system and Malaysia’s Ministry of Foreign Affairs. The operators also scanned and attempted to exploit infrastructure in Hong Kong’s education sector.

TriBack Loader is a custom loader that employs DLL sideloading, reversing encrypted payloads using XOR encryption and executing shellcode through Win32 calls, often bypassing EDR detection. The loader utilizes various techniques, including InitOnceExecuteOnce and a TimerQueue callback, and an undocumented thread-creation routine (EtwpCreateEtwThread) to evade detection. The operation leverages a fake Claude website (claude-pro[.]com) to distribute spear-phishing campaigns, impersonating Anthropic’s Claude software.

Sophos identified a malvertising campaign linked to the operation, suggesting the fake Claude site was used to reach users searching for a legitimate Claude download. The operation exploited several vulnerabilities, including CVE-2018-11511 in ASUSTOR ADM, CVE-2021-24139 in the 10Web Photo Gallery WordPress plugin, CVE-2021-31755 in Tenda AC11 routers, and CVE-2021-32305 in WebSVN. These vulnerabilities have a CVSS base score of 9.8.

The operation also ran Nuclei with critical-severity templates against 14,653 Hong Kong education-related URLs, surfacing 13 unique vulnerabilities. Group-IB prioritizes internet-facing Java applications and systems carrying unpatched 9.8-rated flaws.

Technical details

  • Affected Products: ASUSTOR ADM, 10Web Photo Gallery, Tenda AC11 routers, WebSVN
  • CVEs Exploited: CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, CVE-2021-32305
  • Attack Vector: Spear-phishing, DLL sideloading, exploitation of publicly disclosed vulnerabilities.
  • Exploitation Status: Active
  • CVSS Scores: 9.8 (for all exploited CVEs)

Impact The operation targets government, healthcare, and education organizations in Asia and Latin America. The exploitation of publicly disclosed vulnerabilities poses a significant risk to these sectors. The use of a fake Claude website indicates a broad reach beyond initial targets.

What to do

  • Flag signed vendor binaries running from user-writable, temporary, or Startup directories, especially when an encrypted .dat or .log file sits in the same folder.
  • Look for unexpected copies of hostfxr.dll, avk.dll, or MpClient.dll, plus nested _CL_###### folders and ~del.vbs.bat.
  • Block or investigate the following domains: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com.
  • Group-IB recommends prioritizing internet-facing Java applications and any public-facing system carrying an unpatched 9.8-rated flaw.

The staging server was 43.106.71[.]28 on port 8000.

Read the full article at The Hacker News