SECURITY·중요도 8·2026. 07. 23.·The Hacker News
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
── KO ──────────────────
중국 관련 JadeProx가 새로운 Windows 로더 TriBack을 사용해 공격 중.
중국 관련 범죄 집단 JadeProx가 정부, 의료 및 교육 기관을 대상으로 TriBack 로더를 사용하여 공격하고 있습니다. Group-IB는 이들의 침해를 추적하며, 알리바바 클라우드의 싱가포르 서버에서 이러한 활동을 발견했습니다. 이를 통해 그들의 공격 방식과 타겟을 파악할 수 있게 되었습니다.
── EN ──────────────────
China-nexus JadeProx is using a new Windows loader, TriBack, in its attacks.
JadeProx, a China-nexus cyber operation, is using a previously undocumented Windows loader called TriBack to target government, healthcare, and education organizations. Group-IB has tracked their activities, discovering an exposed Alibaba Cloud server in Singapore that revealed these attacks. This incident highlights the evolving tactics being used by cybercriminals to exploit various sectors.