hacker-news · Crawled Jul 23, 2026

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

9 IoCs 1 Malware 1 CVEs
Read original article ↗

AI Summary

A China-nexus threat actor tracked as JadeProx has been conducting cyberattacks against government, healthcare, and education sectors in Asia and Latin America using a previously undocumented Windows loader named TriBack Loader. The attacks leverage DLL sideloading techniques and phishing campaigns, including a fake Anthropic Claude website, to deploy backdoors such as Beagle and AdaptixC2. The operators also perform large-scale scanning for known vulnerabilities and maintain persistence via malicious startup entries and webshells.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 9 extracted

Type Value Detail
Domain claude-pro[.]com Details →
Domain license[.]claude-pro[.]com Details →
Domain sylverixstrategy[.]com Details →
Domain gouvvbo[.]top Details →
Domain vertextrust-advisors[.]com Details →
Domain update-trellix[.]com Details →
Domain update-crowdstrike[.]com Details →
Domain update-sentinelone[.]com Details →
IP 43[.]106[.]71[.]28 Details →

MITRE ATT&CK TTPs 33 techniques

T1003.001 LSASS Memory · Credential Access T1006 Direct Volume Access · Defense Evasion T1012 Query Registry · Discovery T1014 Rootkit · Defense Evasion T1027 Obfuscated Files or Information · Defense Evasion T1048 Exfiltration Over Alternative Protocol · Exfiltration T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.015 ListPlanting · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1114 Email Collection · Collection T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1548.002 Bypass User Account Control · Privilege Escalation T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access T1570 Lateral Tool Transfer · Lateral Movement T1588 Obtain Capabilities · Resource Development