China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Reported exploitedTriBack LoaderJadeProxAdaptixC2Our summary
A China-linked cyber operation tracked as JadeProx has deployed a new Windows loader named TriBack Loader to target government, healthcare, and education institutions in Asia and Latin America. The threat actors have leveraged multiple unpatched vulnerabilities including CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, and CVE-2021-32305—each rated with a high CVSS score of 9.8—to gain initial access. Once inside, they used DLL sideloading techniques to execute malicious payloads and deliver post-exploitation tools like AdaptixC2 and Beagle. Sophos and Group-IB have identified spear-phishing campaigns and domain infrastructure linked to the activity, urging organizations to patch exposed Java interfaces and monitor for suspicious file patterns.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.