China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
A China-nexus operation, tracked as JadeProx, has been targeting government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.
Intelligence analysis by Llama

The operation, exposed through an Alibaba Cloud server, has used a custom loader builder to create four infection chains, each with a legitimate signed executable paired with a malicious DLL and an encrypted payload. The loader has been used to deliver various payloads, including AdaptixC2, Beagle, and an unknown payload.
Imagine you're trying to break into a house, but instead of using a key, you use a special tool that helps you get inside. This is kind of like what the hackers in this story are doing. They're using a special tool, called a loader, to help them get into the computers of important organizations like hospitals and governments. But instead of just getting in, they're also trying to hide their tracks and make it harder for the good guys to catch them.
Analysis
A China-Nexus Operation Exposed
The exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. The loader appears in four infection chains built around DLL sideloading, with most recovered builds pairing a legitimate signed executable with a malicious DLL and an encrypted .dat or .log payload.
A Custom Loader Builder
The repeated API sequence suggests a custom loader builder, the researchers say. Two variants delivered AdaptixC2, an open-source post-exploitation framework. A Claude-themed variant used DonutLoader to run Beagle, a backdoor Sophos was first to document. The fourth variant's payload is unknown; its encrypted companion file was never recovered.
A Malicious MSI Installer
The Beagle backdoor it delivered reported to license.claude-pro.com. Sophos, working from the fake site, its hosting infrastructure, and malware samples, found the same reused XOR key in builds going back to February but said a shared key was not enough to conclude one actor. Group-IB, working from the exposed server's contents, groups those builds with the Asian intrusions. It still stops short of naming an established group: tooling moves freely in the China-nexus ecosystem, Group-IB notes, so a match on tools is not a match on operators.
A Scan List and Vulnerability Templates
The operators also ran Nuclei with critical-severity templates only against a list of 14,653 Hong Kong education-related URLs, surfacing 13 unique vulnerabilities. Those 14,653 URLs are a scan list, and the report does not say how many of the follow-ups succeeded. The report names four CVEs the operators attempted against individual hosts, and The Hacker News confirmed all four against NVD on July 23, 2026: CVE-2018-11511 in ASUSTOR ADM, CVE-2021-24139 in the 10Web Photo Gallery WordPress plugin, CVE-2021-31755 in Tenda AC11 routers, and CVE-2021-32305 in WebSVN. Each carries a CVSS base score of 9.8.
Key points
- A China-nexus operation, tracked as JadeProx, has been targeting government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.
- The loader appears in four infection chains built around DLL sideloading, with most recovered builds pairing a legitimate signed executable with a malicious DLL and an encrypted .dat or .log payload.
- The loader has been used to deliver various payloads, including AdaptixC2, Beagle, and an unknown payload.
- The operators also ran Nuclei with critical-severity templates only against a list of 14,653 Hong Kong education-related URLs, surfacing 13 unique vulnerabilities.
If this development plays out positively, it's possible that the exposed server and the JadeProx operation will be taken down, and the hackers will be caught. This could lead to a decrease in the number of attacks and a safer online environment for organizations and individuals.
However, it's also possible that the hackers will find a way to evade detection and continue their operations. This could lead to a continued threat to organizations and individuals, and a potentially devastating impact on the online environment.
Market signals
- XAU Escalation drives safe-haven demand for gold, per the article's framing of investor reaction.
AI-generated analysis of potential market relevance. Not financial advice.



