SPIN Unprocessed July 23, 2026 ai_technology cybersecurity
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
View original on thehackernews.comOverview
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report
SpinGraph analysis pending — check back after processing.
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
More from The Hacker News
View all →- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
- Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
- ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
- Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
- How Synthetic Identity Fraud is Coming for Machine Identities
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO