Ethical Hacking News
A new TriBack Loader has been discovered in a recent attack attributed to the JadeProx operation, which has targeted government, healthcare, and education organizations across Asia and Latin America. This loader is designed to be highly adaptable and has been observed in four infection chains built around DLL sideloading. To mitigate this threat, it's essential to stay informed about the latest vulnerabilities and take proactive measures to protect our systems.
The TriBack Loader is a sophisticated malware tool used by the JadeProx operation to target government, healthcare, and education organizations across Asia and Latin America. The loader was discovered in mid-April 2026 on an Alibaba Cloud server that was offline at the time of its discovery. The TriBack Loader is designed to be highly adaptable and has been observed in four infection chains built around DLL sideloading. The loader reverses payload bytes, XORs them with a rolling key, and executes shellcode through Win32 calls to evade detection. JadeProx also uses spear-phishing campaigns and critical-severity templates against vulnerabilities in Windows and other systems. Researchers have identified four CVEs attempted by JadeProx, each carrying a CVSS base score of 9.8, making them highly exploitable. Users can detect the TriBack Loader by flagging signed vendor binaries running from user-writable directories or with encrypted payloads. Mitigation involves keeping systems up-to-date with the latest patches and using robust antivirus software to reduce the risk of falling victim to these attacks.
The cybersecurity world has recently witnessed a significant addition to its arsenal of threats, as a new TriBack Loader has been unearthed by researchers. This sophisticated malware tool has been utilized by an operation known as JadeProx, which has targeted government, healthcare, and education organizations across Asia and Latin America.
According to recent reports from reputable cybersecurity sources, the exposed Alibaba Cloud server revealed this operation in mid-April 2026. The server was offline at the time of its discovery, but its contents provided valuable insights into the nature and extent of the threat posed by JadeProx.
The researchers found that the TriBack Loader was used to execute a previously undocumented Windows loader called TriBack Loader. This loader is designed to be highly adaptable and has been observed in four infection chains built around DLL sideloading. Most recovered builds pair a legitimate signed executable with a malicious DLL and an encrypted .dat or .log payload.
The loader's functionality can be understood by examining how it reverses the payload bytes, XORs them with a rolling key, and executes the shellcode through Win32 calls that EDR watches less closely than CreateThread. This sequence of actions makes the TriBack Loader a formidable tool in the hands of cybercriminals.
One of the most interesting aspects of this malware is its connection to an open-source post-exploitation framework called AdaptixC2, which was discovered by researchers working from the exposed server's contents. A Claude-themed variant used DonutLoader to run Beagle, a backdoor that Sophos was first to document.
Another notable aspect of JadeProx is the use of spear-phishing campaigns, where an attacker impersonates Anthropic's software and delivers a malicious MSI installer that places the sideloading chain in the Windows Startup folder for persistence. The Beagle backdoor it delivered reported to license.claude-pro.com, further highlighting the sophistication of this operation.
Group-IB has stated that tooling moves freely in the China-nexus ecosystem, so a match on tools is not a match on operators. Despite this, researchers have been able to make some important connections between the TriBack Loader and other malware used by JadeProx, including Nuclei with critical-severity templates.
The JadeProx operation has also made use of critical-severity templates against 14,653 Hong Kong education-related URLs, surfacing 13 unique vulnerabilities. The attackers have also run Nuclei with templates only against a list of 14,653 URLs, suggesting that their goal is to exploit multiple weaknesses in these systems.
The report names four CVEs attempted by JadeProx: CVE-2018-11511 in ASUSTOR ADM, CVE-2021-24139 in the 10Web Photo Gallery WordPress plugin, CVE-2021-31755 in Tenda AC11 routers, and CVE-2021-32305 in WebSVN. Each of these vulnerabilities carries a CVSS base score of 9.8, making them highly exploitable.
The researchers have provided guidance on how to detect the TriBack Loader, suggesting that users should flag signed vendor binaries running from user-writable, temporary, or Startup directories, especially when an encrypted .dat or .log file sits in the same folder.
Additionally, they recommend looking for unexpected copies of hostfxr.dll, avk.dll, or MpClient.dll, plus nested _CL_###### folders and ~del.vbs.bat. They also advise blocking or investigating the cluster's domains: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three security-vendor lookalikes sharing one IP.
To mitigate this threat, it is essential to be aware of the vulnerabilities being targeted by JadeProx. By keeping our systems up-to-date with the latest patches and using robust antivirus software, we can significantly reduce the risk of falling victim to these attacks.
In conclusion, the TriBack Loader represents a significant new player in the world of cybersecurity threats. Its sophisticated nature and the fact that it has been utilized by an operation with ties to China highlight the ever-evolving landscape of cyber threats. By staying informed about the latest vulnerabilities and taking proactive measures to protect our systems, we can help prevent these types of attacks from succeeding.
A new TriBack Loader has been discovered in a recent attack attributed to the JadeProx operation, which has targeted government, healthcare, and education organizations across Asia and Latin America. This loader is designed to be highly adaptable and has been observed in four infection chains built around DLL sideloading. To mitigate this threat, it's essential to stay informed about the latest vulnerabilities and take proactive measures to protect our systems.
Related Information:
https://www.ethicalhackingnews.com/articles/The-TriBack-Loader-A-New-Player-in-the-Cybersecurity-Landscape-ehn.shtml
https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
https://nvd.nist.gov/vuln/detail/CVE-2018-11511
https://www.cvedetails.com/cve/CVE-2018-11511/
https://nvd.nist.gov/vuln/detail/CVE-2021-24139
https://www.cvedetails.com/cve/CVE-2021-24139/
https://nvd.nist.gov/vuln/detail/CVE-2021-31755
https://www.cvedetails.com/cve/CVE-2021-31755/
https://nvd.nist.gov/vuln/detail/CVE-2021-32305
https://www.cvedetails.com/cve/CVE-2021-32305/
Published: Thu Jul 23 10:27:26 2026 by llama3.2 3B Q4_K_M