JadeProx Exposed: Unveiling TriBack Loader & China-Nexus C2 Infrastructure

JadeProx TriBack Loader infection chain and open directory C2 infrastructure diagram
JadeProx victimology map | Image: Group-IB

An Unprotected Directory Exposes Espionage Operations

A single overlooked server misconfiguration inadvertently exposed the inner workings of an entire China-nexus cyber espionage infrastructure. Cybersecurity specialists at Group-IB gained access to an exposed directory, uncovering command logs, malicious binaries, victim organization registries, and pre-packaged phishing lures.

The server operated within Alibaba Cloud infrastructure and belonged to operators behind the JadeProx campaign. In mid-April 2026, threat actors left a Python web server running with open directory listing enabled. This operational security blunder allowed researchers to reconstruct the timeline and tactics of attacks targeting government entities, healthcare institutions, and educational facilities across Southeast Asia and Latin America. You can read the comprehensive technical analysis in Group-IB’s report on the JadeProx China-nexus campaign and TriBack Loader.

High-Profile Targets Across Global Regions

High-profile targets included the medical imaging processing system of a Vietnamese hospital, the Ministry of Foreign Affairs of Malaysia, and educational institutions in Hong Kong. In a parallel campaign, threat actors dispatched a forged invoice purportedly originating from a major local brewery to the National Congress of Honduras. Furthermore, the hackers crafted a counterfeit portal mimicking the Municipal Tax Administration of Venezuela to harvest credentials and sensitive documents.

The TriBack Loader Framework

The core operational component of JadeProx is the TriBack Loader malware family. This loader executes alongside legitimate, signed binaries from reputable vendors, decrypting hidden payloads and transferring execution control through infrequently monitored Windows API functions. This stealthy methodology enables the malware to bypass security controls that typically monitor conventional execution mechanisms.

Group-IB researchers identified four distinct variants of TriBack Loader:

  • Two variants deployed AdaptixC2, an open-source command-and-control framework used for remote endpoint management.
  • A third variant dropped a previously unknown backdoor designated as Beagle.
  • A fourth sample was discovered within a “DeviceSync” archive, though its final payload could not be conclusively determined.

Claude Pro Lures and Infrastructure Operations

To distribute malicious payloads, operators utilized documents and installers disguised as Claude Pro software. One archive contained technical documentation for Anthropic’s service, while another prompted users to install a rogue application build. Upon execution, the malware suite established persistence in the Windows Startup folder, ensuring uninterrupted access across system reboots.

The open directory server also hosted vulnerability scanners, covert tunneling tools, network proxies, and defense evasion utilities tailored for Alibaba Cloud environments. Command histories revealed that the threat actors conducted automated reconnaissance against thousands of Hong Kong educational domains, searching for critical vulnerabilities and manually attempting to establish persistence on compromised hosts.

Attribution and Strategic Assessment

Group-IB associates JadeProx with the broader Chinese cyber espionage ecosystem, though they stop short of attributing the campaign to a single, specific advanced persistent threat (APT) group. Tactics, techniques, and procedures (TTPs) overlap with known threat actors, including Mustang Panda, Tropic Trooper, Earth Lusca, and APT27. However, the complete intrusion profile does not align entirely with any single known entity.

Specialists identify the primary hallmarks of JadeProx as the proprietary TriBack Loader family, recurring cryptographic key reuse, and shared server infrastructure. The open directory blunder provided an unprecedented glimpse into the full attack lifecycle from lure preparation to command-and-control network administration.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply