Infosec News Nuggets — July 24, 2026
Brief
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Group-IB uncovered an exposed Alibaba Cloud server tied to a China-linked operation dubbed JadeProx, revealing a previously undocumented Windows loader called TriBack that was used against government, healthcare, and education targets across Asia and Latin America, including active intrusions into a Vietnamese hospital’s medical imaging system and Malaysia’s foreign ministry.
The loader relies on DLL sideloading across four infection chains, with one variant impersonating a Claude desktop installer to deliver a backdoor that researchers say may have spread through malvertising to ordinary users searching for the app.
