SECURITY·중요도 8·2026. 07. 23.·The Hacker News

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

── KO ──────────────────

중국 관련 JadeProx가 새로운 Windows 로더 TriBack을 사용해 공격 중.

중국 관련 범죄 집단 JadeProx가 정부, 의료 및 교육 기관을 대상으로 TriBack 로더를 사용하여 공격하고 있습니다. Group-IB는 이들의 침해를 추적하며, 알리바바 클라우드의 싱가포르 서버에서 이러한 활동을 발견했습니다. 이를 통해 그들의 공격 방식과 타겟을 파악할 수 있게 되었습니다.


── EN ──────────────────

China-nexus JadeProx is using a new Windows loader, TriBack, in its attacks.

JadeProx, a China-nexus cyber operation, is using a previously undocumented Windows loader called TriBack to target government, healthcare, and education organizations. Group-IB has tracked their activities, discovering an exposed Alibaba Cloud server in Singapore that revealed these attacks. This incident highlights the evolving tactics being used by cybercriminals to exploit various sectors.

원문 보기 →목록으로