JadeProx: China-Nexus Campaign Deploys TriBack Loader Against Government, Healthcare, and Education Targets in APAC and Latin America
JadeProx: China-Nexus Campaign Deploys TriBack Loader (TL-2026-1653), also tracked as JadeProx, is a high-severity advanced persistent threat campaign scored CVSS 9.8, first published 2026-07-23. It is attributed to JadeProx (China) with medium confidence, affects ASUSTOR ASUSTOR Data Master (ADM) photo gallery, references 4 CVEs (CVE-2018-11511, CVE-2021-24139, CVE-2021-31755), maps to 37 MITRE ATT&CK techniques (T1005, T1027.013, T1036.005), and is covered by 9 detection rules and 62 indicators of compromise.
Key facts for TL-2026-1653
- Threat ID
- TL-2026-1653
- Also known as
- JadeProx
- Severity
- HIGH
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-07-23
- Last reviewed
- 2026-07-23
- Attribution
- JadeProx
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, health, education, municipal administration, financial services spoofed
- Target regions
- Southeast Asia, Latin America, vietnam, malaysia, hong kong, honduras, venezuela
- Detection rules
- 9
- Indicators of compromise
- 62
- Updates
- 2026-07-23 · 2 updates · revalidated 2× · latest source
Malware and tooling in JadeProx: China-Nexus Campaign Deploys TriBack Loader
Malware and tooling: AdaptixC2, Bagle, DonutLoader, TriBack Loader, NPS, Neo-reGeorg, XMRig Proxy, fscan, iox, nuclei, suo5
Group-IB discovered an exposed Alibaba Cloud staging server (43.106.71[.]28) revealing an active China-nexus operation, tracked as JadeProx, that compromised government, healthcare, and education organizations across Vietnam, Malaysia, Hong Kong, Honduras, and Venezuela using a custom shellcode loader (TriBack Loader) and post-exploitation tooling including AdaptixC2 and Beagle.
How JadeProx: China-Nexus Campaign Deploys TriBack Loader works
JadeProx is a China-nexus threat cluster identified by Group-IB after an exposed Alibaba Cloud OSS staging server (43.106.71[.]28:8000, hosted in Singapore) was found with open Python directory listing, revealing the operator's complete toolkit, bash history, and victim access paths. The operation ran simultaneous intrusions against government, healthcare, and education entities in Vietnam (hospital PACS/JMX systems), Malaysia (Ministry of Foreign Affairs), Hong Kong (14+ education institutions, 14,653 nuclei scan targets), Honduras (government networks via a beverage-company-themed phishing lure), and Venezuela (a municipal tax portal). The intrusion set is unified by the TriBack Loader malware framework: a three-file triad (signed EXE + malicious DLL + encrypted DAT/LOG) that uses DLL sideloading against legitimate signed binaries (ServiceHub.DataWarehouseHost.exe, Microsoft Service Hub AnyCPU, avk.exe from G DATA, MpCopyAccelerator.exe), decrypts its payload with a two-stage byte-reversal-plus-rolling-XOR routine, and executes shellcode through Win32 callback APIs (InitOnceExecuteOnce, TimerQueue, EtwpCreateEtwThread) to evade EDR hooking. Four variants were identified, delivering AdaptixC2 (variants 1-2) or Beagle via DonutLoader shellcode injection (variant 3). Initial access combines exploitation of internet-facing applications (four CVSS-9.8 CVEs: ASUSTOR ADM SQLi, 10Web Photo Gallery SQLi, Tenda AC11 buffer overflow, WebSVN command injection) with spearphishing archives containing LNK/VBS droppers and MSI installers themed as 'Estado de Cuenta' account statements (Honduras) and fake Claude-Pro AI software distribution (Anthropic brand impersonation) and GolddTV. Post-exploitation used a Chinese-origin toolkit staged on the exposed server: iox and NPS (port forwarding/proxy tunneling), suo5 (SOCKS5-over-HTTP tunneling), Neo-reGeorg (HTTP tunnel webshell maintenance), nuclei (mass CVE scanning — 14,653 Hong Kong targets alone), fscan (internal network reconnaissance), and XMRig Proxy (cryptomining relay). A Chinese-language fuckaliyun.sh script was used to disable Alibaba Cloud's built-in security agent on compromised OSS infrastructure. Attribution is to a China-nexus ecosystem rather than a single named group; Group-IB tracks it separately as JadeProx to avoid misattribution, citing TTP and tooling overlap with Mustang Panda, Tropic Trooper, Earth Lusca, and APT27, plus a GitHub Pages analytics-cookie beaconing technique previously associated with Tropic Trooper. C2 infrastructure used Cloudflare fronting (sylverixstrategy[.]com), DigitalOcean hosting (gouvvbo[.]top, vertextrust-advisors[.]com), and Alibaba Cloud US (license.claude-pro[.]com), registered via NameSilo. Credential-harvesting phishing portals impersonated a Venezuelan municipal tax authority (Municipality Piar) and a fake financial services firm (Vertex Trust Advisors). Persistence is achieved by dropping the EXE-DLL-DAT triad into the Windows Startup folder, with self-deleting batch/VBS scripts (del.vbs.bat) used to clean forensic traces after execution.
MITRE ATT&CK techniques used in TL-2026-1653
Collection
Defense Evasion
T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1574.001 DLL
Exfiltration
T1041 Exfiltration Over C2 Channel
Discovery
T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Execution
T1059 Command and Scripting Interpreter; T1059.005 Command and Scripting Interpreter: Visual Basic; T1106 Native API; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1090.001 Proxy: Internal Proxy; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1572 Protocol Tunneling; T1573.001 Encrypted Channel: Symmetric Cryptography
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing; T1566.001 Phishing: Spearphishing Attachment
Impact
Credential Access
T1539 Steal Web Session Cookie
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Lateral Movement
Resource Development
T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1585 Establish Accounts; T1587 Develop Capabilities; T1588.002 Obtain Capabilities: Tool
Reconnaissance
Affected products and versions in JadeProx: China-Nexus Campaign Deploys TriBack Loader
- ASUSTOR — ASUSTOR Data Master (ADM) photo gallery
Vulnerable versions: 3.1.0.RFQ3
Fixed in: Later than 3.1.0 - 10Web — Photo Gallery by 10Web (WordPress plugin)
Vulnerable versions: < 1.5.55
Fixed in: 1.5.55+ - Tenda — AC11 router
Vulnerable versions: Firmware through 02.03.01.104_CN
Fixed in: Post 02.03.01.104_CN - WebSVN — WebSVN
Vulnerable versions: < 2.6.1
Fixed in: 2.6.1+ - Microsoft — ServiceHub.DataWarehouseHost.exe (abused for DLL sideloading)
Vulnerable versions: N/A - abused legitimate signed binary
Fixed in: N/A - G DATA — avk.exe (abused for DLL sideloading)
Vulnerable versions: N/A - abused legitimate signed binary
Fixed in: N/A
Remediation for JadeProx: China-Nexus Campaign Deploys TriBack Loader
Patches
- Patch ASUSTOR ADM to a version beyond 3.1.0 (CVE-2018-11511)
- Update 10Web Photo Gallery WordPress plugin to 1.5.55+ (CVE-2021-24139)
- Update Tenda AC11 firmware beyond 02.03.01.104_CN (CVE-2021-31755)
- Update WebSVN to 2.6.1+ (CVE-2021-32305)
Immediate actions
- Block all listed C2 and staging-server IOCs (domains, IPs) at DNS/perimeter firewall
- Hunt for TriBack Loader signed-binary/DLL/DAT triads (ServiceHub.DataWarehouseHost.exe, avk.exe, MpCopyAccelerator.exe) in Startup folders
- Search endpoints for loader DLLs by name: hostfxr.dll, avk.dll, MpClient.dll placed alongside encrypted .dat/.log companion files
- Hunt for '_CL_######' nested folder path patterns associated with staging
- Quarantine and forensically image any host that executed Claude.msi or GolddTV.msi
- Alert on vendor-signed binaries (G DATA avk.exe, Microsoft ServiceHub) launching from Startup or temp directories with unexpected companion files
Workarounds
- Take internet-exposed hospital PACS/JMX interfaces off public exposure or place behind VPN
- Restrict internet exposure of government/municipal web portals pending patching
- Monitor MSI installations that trigger VBScript custom actions
Longer-term hardening
- Deploy EDR with callback-API/thread-hijack behavioral detection (InitOnceExecuteOnce, TimerQueue, EtwpCreateEtwThread abuse)
- Restrict outbound SOCKS5-over-HTTP and internal proxy tunneling (suo5, iox, NPS) via egress filtering and TLS inspection
- Implement application allowlisting to block DLL sideloading against signed but unexpected binaries
- Deploy threat intelligence feeds for proactive IOC and infrastructure-pattern blocking
CVEs associated with JadeProx: China-Nexus Campaign Deploys TriBack Loader
CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, CVE-2021-32305
Weaknesses (CWE) in JadeProx: China-Nexus Campaign Deploys TriBack Loader
CWE-89, CWE-787, CWE-78
Timeline of JadeProx: China-Nexus Campaign Deploys TriBack Loader
- First observed TriBack Loader build: avk.dll variant sideloaded via G DATA avk.exe, delivering Beagle via DonutLoader shellcode injection.
- MpClient.dll loader variant compiled, part of the ongoing TriBack Loader development cycle.
- TriBack Loader variant 4 (MpCopyAccelerator.exe sideloading) built, associated with DeviceSync targeting.
- TriBack Loader variant 1 (hostfxr.dll sideloaded via ServiceHub.DataWarehouseHost.exe, InitOnceExecuteOnce callback) compiled, delivering AdaptixC2.
- C2 domain sylverixstrategy[.]com registered via NameSilo, later fronted through Cloudflare.
- AdaptixC2 beacons compiled for use with TriBack Loader variants 1 and 2.
- TriBack Loader variant 2 (Microsoft Service Hub AnyCPU sideloading, TimerQueue callback) compiled, delivering AdaptixC2.
- Honduras-targeted 'Estado de Cuenta' phishing campaign launched, impersonating a beverage company to deliver malicious ZIP/MSI archives.
- Claude-Pro brand-impersonation phishing campaign launched, distributing Claude.msi as a fake AI software installer.
- Open-directory Python HTTP staging server at 43.106.71[.]28:8000 observed actively serving the operator's toolkit and payloads.
- Group-IB researchers discovered the exposed Alibaba Cloud staging server in mid-April 2026, revealing bash history, victim access paths, and the full post-exploitation toolkit.
- Exposed Alibaba Cloud staging server taken offline by the operators shortly before public disclosure.
- Group-IB publicly disclosed the JadeProx campaign, TriBack Loader analysis, and associated IOCs via its threat intelligence blog.
Update history for TL-2026-1653
- 2026-07-23 — China-Nexus JadeProx Uses New TriBack Loader to Deploy AdaptixC2 and Beagle Backdoor via Fake Claude AI Site: What changed No severity/exploitability/status escalation - both reports rate the campaign HIGH/ACTIVE with MEDIUM attribution confidence. The newer reporting (Sophos, TheHackerNews, CyberPress corroboration) substantially expands the evide
- 2026-07-23 — TriBack Loader / JadeProx Campaign Exposed via Alibaba Cloud OPSEC Failure — AdaptixC2 and Beagle Backdoor Deployment Against Government, Healthcare, and Education Targets: What changed No severity/exploitability/status escalation - both reports rate the campaign HIGH/ACTIVE with MEDIUM attribution confidence. The newer reporting (Sophos, TheHackerNews, CyberPress corroboration) substantially expands the evide
Sources cited for JadeProx: China-Nexus Campaign Deploys TriBack Loader
Threats related to JadeProx: China-Nexus Campaign Deploys TriBack Loader
- Fake Claude AI Download Site Delivers Trojanized Installer Deploying PlugX RAT via G DATA DLL Sideloading
- Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers, Backdoors and Malicious Browser Extensions
- Mustang Panda PlugX RAT — Multi-Stage Fake Browser Update Chain via G DATA AntiVirus DLL Sideloading (BlueCyber)
- BlackTech Deploys BlueShell Linux Backdoor Against Japanese Organizations
- China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets
- Dust Specter APT — Iran-Nexus Targeting Iraqi Government Officials with TWINTASK/GHOSTFORM Malware
Detection coverage for TL-2026-1653
As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1653 across Splunk SPL, Microsoft KQL and Sigma, covering 62 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.