JadeProx: China-Nexus Campaign Deploys TriBack Loader Against Government, Healthcare, and Education Targets in APAC and Latin America — Threadlinqs Intelligence
As of 2026-07-23, JadeProx: China-Nexus Campaign Deploys TriBack Loader Against Government, Healthcare, and Education Targets in APAC and Latin America is a high-severity apt threat attributed to JadeProx (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 62 indicators of compromise.
Threat ID: TL-2026-1653 · Severity: HIGH · CVSS: 9.8 · Status: ACTIVE · Category: APT
Updated: 2026-07-23 · 2 updates · revalidated 2× · latest source
Attribution: JadeProx · China · ESPIONAGE
Group-IB discovered an exposed Alibaba Cloud staging server (43.106.71[.]28) revealing an active China-nexus operation, tracked as JadeProx, that compromised government, healthcare, and education
JadeProx is a China-nexus threat cluster identified by Group-IB after an exposed Alibaba Cloud OSS staging server (43.106.71[.]28:8000, hosted in Singapore) was found with open Python directory listing, revealing the operator's complete toolkit, bash history, and victim access paths. The operation ran simultaneous intrusions against government, healthcare, and education entities in Vietnam (hospital PACS/JMX systems), Malaysia (Ministry of Foreign Affairs), Hong Kong (14+ education institutions, 14,653 nuclei scan targets), Honduras (government networks via a beverage-company-themed phishing lure), and Venezuela (a municipal tax portal). The intrusion set is unified by the TriBack Loader malware framework: a three-file triad (signed EXE + malicious DLL + encrypted DAT/LOG) that uses DLL sideloading against legitimate signed binaries (ServiceHub.DataWarehouseHost.exe, Microsoft Service Hub AnyCPU, avk.exe from G DATA, MpCopyAccelerator.exe), decrypts its payload with a two-stage byte-reversal-plus-rolling-XOR routine, and executes shellcode through Win32 callback APIs (InitOnceExecuteOnce, TimerQueue, EtwpCreateEtwThread) to evade EDR hooking. Four variants were identified, delivering AdaptixC2 (variants 1-2) or Beagle via DonutLoader shellcode injection (variant 3). Initial access combines exploitation of internet-facing applications (four CVSS-9.8 CVEs: ASUSTOR ADM SQLi, 10Web Photo Gallery SQLi, Tenda AC11 buffer overflow, WebSVN command injection) with spearphishing archives containing LNK/VBS droppers and MSI installers themed as 'Estado de Cuenta' account statements (Honduras) and fake Claude-Pro AI software distribution (Anthropic brand impersonation) and GolddTV. Post-exploitation used a Chinese-origin toolkit staged on the exposed server: iox and NPS (port forwarding/proxy tunneling), suo5 (SOCKS5-over-HTTP tunneling), Neo-reGeorg (HTTP tunnel webshell maintenance), nuclei (mass CVE scanning — 14,653 Hong Kong targets alone), fscan (internal network reconnaissance), and XMRig Proxy (cryptomining relay). A Chinese-language fuckaliyun.sh script was used to disable Alibaba Cloud's built-in security agent on compromised OSS infrastructure. Attribution is to a China-nexus ecosystem rather than a single named group; Group-IB tracks it separately as JadeProx to avoid misattribution, citing TTP and tooling overlap with Mustang Panda, Tropic Trooper, Earth Lusca, and APT27, plus a GitHub Pages analytics-cookie beaconing technique previously associated with Tropic Trooper. C2 infrastructure used Cloudflare fronting (sylverixstrategy[.]com), DigitalOcean hosting (gouvvbo[.]top, vertextrust-advisors[.]com), and Alibaba Cloud US (license.claude-pro[.]com), registered via NameSilo. Credential-harvesting phishing portals impersonated a Venezuelan municipal tax authority (Municipality Piar) and a fake financial services firm (Vertex Trust Advisors). Persistence is achieved by dropping the EXE-DLL-DAT triad into the Windows Startup folder, with self-deleting batch/VBS scripts (del.vbs.bat) used to clean forensic traces after execution.
Weaknesses (CWE)
CWE-89, CWE-787, CWE-78
Target sectors: government administration, health, education, municipal administration, financial services spoofed
Target regions: Southeast Asia, Latin America, vietnam, malaysia, hong kong, honduras, venezuela
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 62 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, CVE-2021-32305, T1595.002, T1583.001, T1583.006, T1588.002, T1190, T1566.001, T1204.002, T1059.005, T1547.001, T1574.001