JadeProx Exposed: Unveiling TriBack Loader & China-Nexus C2 Infrastructure

An Unprotected Directory Exposes Espionage Operations
A single overlooked server misconfiguration inadvertently exposed the inner workings of an entire China-nexus cyber espionage infrastructure. Cybersecurity specialists at Group-IB gained access to an exposed directory, uncovering command logs, malicious binaries, victim organization registries, and pre-packaged phishing lures.
The server operated within Alibaba Cloud infrastructure and belonged to operators behind the JadeProx campaign. In mid-April 2026, threat actors left a Python web server running with open directory listing enabled. This operational security blunder allowed researchers to reconstruct the timeline and tactics of attacks targeting government entities, healthcare institutions, and educational facilities across Southeast Asia and Latin America. You can read the comprehensive technical analysis in Group-IB’s report on the JadeProx China-nexus campaign and TriBack Loader.
High-Profile Targets Across Global Regions
High-profile targets included the medical imaging processing system of a Vietnamese hospital, the Ministry of Foreign Affairs of Malaysia, and educational institutions in Hong Kong. In a parallel campaign, threat actors dispatched a forged invoice purportedly originating from a major local brewery to the National Congress of Honduras. Furthermore, the hackers crafted a counterfeit portal mimicking the Municipal Tax Administration of Venezuela to harvest credentials and sensitive documents.
The TriBack Loader Framework
The core operational component of JadeProx is the TriBack Loader malware family. This loader executes alongside legitimate, signed binaries from reputable vendors, decrypting hidden payloads and transferring execution control through infrequently monitored Windows API functions. This stealthy methodology enables the malware to bypass security controls that typically monitor conventional execution mechanisms.
Group-IB researchers identified four distinct variants of TriBack Loader:
- Two variants deployed AdaptixC2, an open-source command-and-control framework used for remote endpoint management.
- A third variant dropped a previously unknown backdoor designated as Beagle.
- A fourth sample was discovered within a “DeviceSync” archive, though its final payload could not be conclusively determined.
Claude Pro Lures and Infrastructure Operations
To distribute malicious payloads, operators utilized documents and installers disguised as Claude Pro software. One archive contained technical documentation for Anthropic’s service, while another prompted users to install a rogue application build. Upon execution, the malware suite established persistence in the Windows Startup folder, ensuring uninterrupted access across system reboots.
The open directory server also hosted vulnerability scanners, covert tunneling tools, network proxies, and defense evasion utilities tailored for Alibaba Cloud environments. Command histories revealed that the threat actors conducted automated reconnaissance against thousands of Hong Kong educational domains, searching for critical vulnerabilities and manually attempting to establish persistence on compromised hosts.
Attribution and Strategic Assessment
Group-IB associates JadeProx with the broader Chinese cyber espionage ecosystem, though they stop short of attributing the campaign to a single, specific advanced persistent threat (APT) group. Tactics, techniques, and procedures (TTPs) overlap with known threat actors, including Mustang Panda, Tropic Trooper, Earth Lusca, and APT27. However, the complete intrusion profile does not align entirely with any single known entity.
Specialists identify the primary hallmarks of JadeProx as the proprietary TriBack Loader family, recurring cryptographic key reuse, and shared server infrastructure. The open directory blunder provided an unprecedented glimpse into the full attack lifecycle from lure preparation to command-and-control network administration.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.