JadeProx: China-Nexus Campaign Deploys TriBack Loader Against Government, Healthcare, and Education Targets in APAC and Latin America

JadeProx: China-Nexus Campaign Deploys TriBack Loader (TL-2026-1653), also tracked as JadeProx, is a high-severity advanced persistent threat campaign scored CVSS 9.8, first published 2026-07-23. It is attributed to JadeProx (China) with medium confidence, affects ASUSTOR ASUSTOR Data Master (ADM) photo gallery, references 4 CVEs (CVE-2018-11511, CVE-2021-24139, CVE-2021-31755), maps to 37 MITRE ATT&CK techniques (T1005, T1027.013, T1036.005), and is covered by 9 detection rules and 62 indicators of compromise.

Key facts for TL-2026-1653

Threat ID
TL-2026-1653
Also known as
JadeProx
Severity
HIGH
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
APT
First published
2026-07-23
Last reviewed
2026-07-23
Attribution
JadeProx
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, health, education, municipal administration, financial services spoofed
Target regions
Southeast Asia, Latin America, vietnam, malaysia, hong kong, honduras, venezuela
Detection rules
9
Indicators of compromise
62
Updates
2026-07-23 · 2 updates · revalidated 2× · latest source

Malware and tooling in JadeProx: China-Nexus Campaign Deploys TriBack Loader

Malware and tooling: AdaptixC2, Bagle, DonutLoader, TriBack Loader, NPS, Neo-reGeorg, XMRig Proxy, fscan, iox, nuclei, suo5

Group-IB discovered an exposed Alibaba Cloud staging server (43.106.71[.]28) revealing an active China-nexus operation, tracked as JadeProx, that compromised government, healthcare, and education organizations across Vietnam, Malaysia, Hong Kong, Honduras, and Venezuela using a custom shellcode loader (TriBack Loader) and post-exploitation tooling including AdaptixC2 and Beagle.

How JadeProx: China-Nexus Campaign Deploys TriBack Loader works

JadeProx is a China-nexus threat cluster identified by Group-IB after an exposed Alibaba Cloud OSS staging server (43.106.71[.]28:8000, hosted in Singapore) was found with open Python directory listing, revealing the operator's complete toolkit, bash history, and victim access paths. The operation ran simultaneous intrusions against government, healthcare, and education entities in Vietnam (hospital PACS/JMX systems), Malaysia (Ministry of Foreign Affairs), Hong Kong (14+ education institutions, 14,653 nuclei scan targets), Honduras (government networks via a beverage-company-themed phishing lure), and Venezuela (a municipal tax portal). The intrusion set is unified by the TriBack Loader malware framework: a three-file triad (signed EXE + malicious DLL + encrypted DAT/LOG) that uses DLL sideloading against legitimate signed binaries (ServiceHub.DataWarehouseHost.exe, Microsoft Service Hub AnyCPU, avk.exe from G DATA, MpCopyAccelerator.exe), decrypts its payload with a two-stage byte-reversal-plus-rolling-XOR routine, and executes shellcode through Win32 callback APIs (InitOnceExecuteOnce, TimerQueue, EtwpCreateEtwThread) to evade EDR hooking. Four variants were identified, delivering AdaptixC2 (variants 1-2) or Beagle via DonutLoader shellcode injection (variant 3). Initial access combines exploitation of internet-facing applications (four CVSS-9.8 CVEs: ASUSTOR ADM SQLi, 10Web Photo Gallery SQLi, Tenda AC11 buffer overflow, WebSVN command injection) with spearphishing archives containing LNK/VBS droppers and MSI installers themed as 'Estado de Cuenta' account statements (Honduras) and fake Claude-Pro AI software distribution (Anthropic brand impersonation) and GolddTV. Post-exploitation used a Chinese-origin toolkit staged on the exposed server: iox and NPS (port forwarding/proxy tunneling), suo5 (SOCKS5-over-HTTP tunneling), Neo-reGeorg (HTTP tunnel webshell maintenance), nuclei (mass CVE scanning — 14,653 Hong Kong targets alone), fscan (internal network reconnaissance), and XMRig Proxy (cryptomining relay). A Chinese-language fuckaliyun.sh script was used to disable Alibaba Cloud's built-in security agent on compromised OSS infrastructure. Attribution is to a China-nexus ecosystem rather than a single named group; Group-IB tracks it separately as JadeProx to avoid misattribution, citing TTP and tooling overlap with Mustang Panda, Tropic Trooper, Earth Lusca, and APT27, plus a GitHub Pages analytics-cookie beaconing technique previously associated with Tropic Trooper. C2 infrastructure used Cloudflare fronting (sylverixstrategy[.]com), DigitalOcean hosting (gouvvbo[.]top, vertextrust-advisors[.]com), and Alibaba Cloud US (license.claude-pro[.]com), registered via NameSilo. Credential-harvesting phishing portals impersonated a Venezuelan municipal tax authority (Municipality Piar) and a fake financial services firm (Vertex Trust Advisors). Persistence is achieved by dropping the EXE-DLL-DAT triad into the Windows Startup folder, with self-deleting batch/VBS scripts (del.vbs.bat) used to clean forensic traces after execution.

MITRE ATT&CK techniques used in TL-2026-1653

Collection

T1005 Data from Local System

Defense Evasion

T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1574.001 DLL

Exfiltration

T1041 Exfiltration Over C2 Channel

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Execution

T1059 Command and Scripting Interpreter; T1059.005 Command and Scripting Interpreter: Visual Basic; T1106 Native API; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1090.001 Proxy: Internal Proxy; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1572 Protocol Tunneling; T1573.001 Encrypted Channel: Symmetric Cryptography

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing; T1566.001 Phishing: Spearphishing Attachment

Impact

T1496 Resource Hijacking

Credential Access

T1539 Steal Web Session Cookie

Persistence

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Lateral Movement

T1570 Lateral Tool Transfer

Resource Development

T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1585 Establish Accounts; T1587 Develop Capabilities; T1588.002 Obtain Capabilities: Tool

Reconnaissance

T1595.002 Active Scanning: Vulnerability Scanning

Affected products and versions in JadeProx: China-Nexus Campaign Deploys TriBack Loader

  • ASUSTOR — ASUSTOR Data Master (ADM) photo gallery
    Vulnerable versions: 3.1.0.RFQ3
    Fixed in: Later than 3.1.0
  • 10Web — Photo Gallery by 10Web (WordPress plugin)
    Vulnerable versions: < 1.5.55
    Fixed in: 1.5.55+
  • Tenda — AC11 router
    Vulnerable versions: Firmware through 02.03.01.104_CN
    Fixed in: Post 02.03.01.104_CN
  • WebSVN — WebSVN
    Vulnerable versions: < 2.6.1
    Fixed in: 2.6.1+
  • Microsoft — ServiceHub.DataWarehouseHost.exe (abused for DLL sideloading)
    Vulnerable versions: N/A - abused legitimate signed binary
    Fixed in: N/A
  • G DATA — avk.exe (abused for DLL sideloading)
    Vulnerable versions: N/A - abused legitimate signed binary
    Fixed in: N/A

Remediation for JadeProx: China-Nexus Campaign Deploys TriBack Loader

Patches

  • Patch ASUSTOR ADM to a version beyond 3.1.0 (CVE-2018-11511)
  • Update 10Web Photo Gallery WordPress plugin to 1.5.55+ (CVE-2021-24139)
  • Update Tenda AC11 firmware beyond 02.03.01.104_CN (CVE-2021-31755)
  • Update WebSVN to 2.6.1+ (CVE-2021-32305)

Immediate actions

  • Block all listed C2 and staging-server IOCs (domains, IPs) at DNS/perimeter firewall
  • Hunt for TriBack Loader signed-binary/DLL/DAT triads (ServiceHub.DataWarehouseHost.exe, avk.exe, MpCopyAccelerator.exe) in Startup folders
  • Search endpoints for loader DLLs by name: hostfxr.dll, avk.dll, MpClient.dll placed alongside encrypted .dat/.log companion files
  • Hunt for '_CL_######' nested folder path patterns associated with staging
  • Quarantine and forensically image any host that executed Claude.msi or GolddTV.msi
  • Alert on vendor-signed binaries (G DATA avk.exe, Microsoft ServiceHub) launching from Startup or temp directories with unexpected companion files

Workarounds

  • Take internet-exposed hospital PACS/JMX interfaces off public exposure or place behind VPN
  • Restrict internet exposure of government/municipal web portals pending patching
  • Monitor MSI installations that trigger VBScript custom actions

Longer-term hardening

  • Deploy EDR with callback-API/thread-hijack behavioral detection (InitOnceExecuteOnce, TimerQueue, EtwpCreateEtwThread abuse)
  • Restrict outbound SOCKS5-over-HTTP and internal proxy tunneling (suo5, iox, NPS) via egress filtering and TLS inspection
  • Implement application allowlisting to block DLL sideloading against signed but unexpected binaries
  • Deploy threat intelligence feeds for proactive IOC and infrastructure-pattern blocking

CVEs associated with JadeProx: China-Nexus Campaign Deploys TriBack Loader

CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, CVE-2021-32305

Weaknesses (CWE) in JadeProx: China-Nexus Campaign Deploys TriBack Loader

CWE-89, CWE-787, CWE-78

Timeline of JadeProx: China-Nexus Campaign Deploys TriBack Loader

  • First observed TriBack Loader build: avk.dll variant sideloaded via G DATA avk.exe, delivering Beagle via DonutLoader shellcode injection.
  • MpClient.dll loader variant compiled, part of the ongoing TriBack Loader development cycle.
  • TriBack Loader variant 4 (MpCopyAccelerator.exe sideloading) built, associated with DeviceSync targeting.
  • TriBack Loader variant 1 (hostfxr.dll sideloaded via ServiceHub.DataWarehouseHost.exe, InitOnceExecuteOnce callback) compiled, delivering AdaptixC2.
  • C2 domain sylverixstrategy[.]com registered via NameSilo, later fronted through Cloudflare.
  • AdaptixC2 beacons compiled for use with TriBack Loader variants 1 and 2.
  • TriBack Loader variant 2 (Microsoft Service Hub AnyCPU sideloading, TimerQueue callback) compiled, delivering AdaptixC2.
  • Honduras-targeted 'Estado de Cuenta' phishing campaign launched, impersonating a beverage company to deliver malicious ZIP/MSI archives.
  • Claude-Pro brand-impersonation phishing campaign launched, distributing Claude.msi as a fake AI software installer.
  • Open-directory Python HTTP staging server at 43.106.71[.]28:8000 observed actively serving the operator's toolkit and payloads.
  • Group-IB researchers discovered the exposed Alibaba Cloud staging server in mid-April 2026, revealing bash history, victim access paths, and the full post-exploitation toolkit.
  • Exposed Alibaba Cloud staging server taken offline by the operators shortly before public disclosure.
  • Group-IB publicly disclosed the JadeProx campaign, TriBack Loader analysis, and associated IOCs via its threat intelligence blog.

Update history for TL-2026-1653

Sources cited for JadeProx: China-Nexus Campaign Deploys TriBack Loader

Threats related to JadeProx: China-Nexus Campaign Deploys TriBack Loader

Detection coverage for TL-2026-1653

As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1653 across Splunk SPL, Microsoft KQL and Sigma, covering 62 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats