Group-IB researchers identified a China-linked threat actor known as JadeProx operating through an exposed Alibaba Cloud server in Singapore. The group deployed a previously unknown Windows loader called TriBack Loader to target government, healthcare, and education institutions across Asia and Latin America.
Researchers discovered the exposed server in mid-April 2026. The infrastructure served as a command-and-control node for JadeProx's malware distribution operations. TriBack Loader functions as a first-stage payload, designed to establish persistence and download secondary malware onto compromised systems. The loader exhibits modular architecture, allowing operators to deploy different payloads based on target value and organizational context.
JadeProx's targeting patterns indicate strategic interest in critical infrastructure and sensitive data. Healthcare organizations face particular risk due to patient records and operational systems exposure. Government agencies targeted likely contain classified information or policy documents. Educational institutions may serve as stepping stones to research facilities or government networks.
TriBack Loader employs obfuscation techniques to evade endpoint detection and response tools. The malware establishes encrypted command channels with remote servers, complicating forensic analysis and incident response efforts. Operators maintain flexibility in payload selection, suggesting operational sophistication and resource availability typical of state-sponsored groups.
The exposure of JadeProx's infrastructure reveals operational security gaps. The Alibaba Cloud misconfiguration left command infrastructure accessible to researchers, creating an unexpected window into active campaign mechanics. Organizations should assume that similar infrastructure exists elsewhere across public cloud providers.
Defenders should implement network-based detection rules for TriBack Loader communications and monitor for suspicious Windows process creation patterns associated with loader execution. Endpoint detection tools require behavioral analytics to identify the reconnaissance and lateral movement phases that follow successful loader deployment. Organizations in targeted regions should prioritize log review of inbound network traffic and process execution timelines from April 2026 forward.
