An exposed Alibaba Cloud staging server revealed a China-nexus espionage operation tracked as JadeProx targeting government, healthcare, and education organizations across Asia and Latin America. Group-IB said the infrastructure exposed command history, phishing kits, webshell paths, tunneling tools, and post-exploitation utilities tied to intrusions involving a Vietnamese public hospital, Malaysia's Ministry of Foreign Affairs, Hong Kong education infrastructure, and phishing activity aimed at Honduras, alongside lures themed around a Venezuelan municipal tax portal.
The campaign used a previously undocumented Windows malware family called TriBack Loader, delivered through four DLL sideloading infection chains and designed to execute shellcode through unusual Windows callback mechanisms to reduce detection. Investigators said different TriBack builds deployed AdaptixC2 beacons or the Beagle backdoor, while operators also ran vulnerability scanning and attempted exploitation of multiple high-severity flaws; a fake Claude-themed site, claude-pro[.]com, was also used to distribute a malicious MSI installer for persistence.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Group-IB analyzed the exposed infrastructure and malware and attributed the activity cluster to JadeProx, describing it as China-nexus espionage activity. The researchers said they could not map it to a known threat group and noted that the tooling is widely shared in that ecosystem.
An operational security mistake left an Alibaba Cloud staging server openly accessible, exposing command history, phishing kits, webshell paths, tunneling tools, post-exploitation utilities, and evidence of active targeting. The exposed server enabled researchers to connect the infrastructure to the broader JadeProx campaign.
The operation used themed lures and fake portals to distribute malware and steal credentials, including a Claude-branded campaign using claude-pro[.]com and a malicious MSI installer. A fake Venezuelan municipal tax portal was also used as part of the broader delivery activity.
During the campaign, the actors used the previously undocumented TriBack Loader in four DLL sideloading-based infection chains. Multiple builds were observed delivering either AdaptixC2 beacons or the Beagle backdoor.
In early 2026, the intrusion cluster tracked as JadeProx conducted espionage activity against government, healthcare, and education organizations across Southeast Asia and Latin America. Reported targeting included a Vietnamese public hospital, Malaysia's Ministry of Foreign Affairs, Hong Kong education infrastructure, and entities in Honduras.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcegroup-ib.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.