# JadeProx Operation Unveiled: Targeting Government and Healthcare Sectors with TriBack Loader

*Published July 24, 2026*
*Source: [https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html](https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html)*

## Executive Summary

A China-linked cyber operation named JadeProx has targeted government, healthcare, and education sectors in Asia and Latin America using the TriBack Loader. The attack utilized DLL sideloading and spear-phishing, revealing vulnerabilities in systems dating back to 2018 and 2021.

## Article

An exposed Alibaba Cloud server has brought to light a China-linked cyber operation known as JadeProx, which has been actively targeting government, healthcare, and education organizations across Asia and Latin America. The operation utilizes a previously undocumented Windows loader called TriBack Loader. According to cybersecurity firm Group-IB, the server was identified in April 2026 within Alibaba Cloud's Singapore region but was offline by the time the report was published in July 2026.

The server's data revealed the operation's activities, including intrusions into a Vietnamese public hospital's medical imaging system and Malaysia's Ministry of Foreign Affairs, along with attempts to exploit Hong Kong's educational infrastructure. The attackers employed spear-phishing tactics, as evidenced by a package aimed at the National Congress of Honduras. They accessed the hospital's imaging server via webshells installed on an exposed Java management interface.

TriBack Loader is executed through DLL sideloading, using a legitimate signed executable paired with a malicious DLL and an encrypted payload. This intricate process involves reversing payload bytes, encrypting them with a rolling key, and executing the shellcode using Win32 calls. The operation involved multiple infection chain variants, suggesting the use of a custom loader builder.

Some variants delivered AdaptixC2, an open-source post-exploitation framework, while others used DonutLoader to deploy Beagle, a backdoor that Sophos first documented. A spear-phishing campaign involved a fake beverage company account statement, and another campaign impersonated Anthropic's Claude software, delivering malware through a malicious MSI installer.

The attackers also conducted scans using Nuclei against 14,653 education-related URLs in Hong Kong, identifying 13 unique vulnerabilities. They attempted to exploit four CVEs, verified by The Hacker News, each with a high CVSS base score. Although tooling matches suggest a China-nexus origin, Group-IB refrains from attributing the operation to a specific group due to the fluid movement of tools within the ecosystem.
