SPIN Unprocessed
Source The Hacker News feeds.feedburner.com Media Center
July 23, 2026 ai_technology cybersecurity

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

View original on thehackernews.com

Overview

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report

SpinGraph analysis pending — check back after processing.

Ask AI about this story

Opens with the SpinGraph .md URL and structured context — one click, prompt included.

More from The Hacker News

View all →

Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO