OPSEC Error Uncovers TriBack Malware in Global Espionage Campaign
Key Takeaways A significant global espionage campaign, dubbed JadeProx, has been exposed due to an operational security (OPSEC) error by its operators. The campaign leverages a newly identified...
Key Takeaways
- A significant global espionage campaign, dubbed JadeProx, has been exposed due to an operational security (OPSEC) error by its operators.
- The campaign leverages a newly identified malware loader, TriBack, to compromise targets across various sectors including healthcare, government, and education.
- Victims span Southeast Asia and Latin America, with specific attacks observed against a Vietnamese hospital, the Malaysian Ministry of Foreign Affairs, and educational institutions in Hong Kong.
- TriBack Loader employs DLL sideloading and unusual Windows callback functions to evade detection, delivering payloads like AdaptixC2 beacons and the Beagle backdoor.
- Defenders should implement network-level blocks, hunt for specific file patterns, and prioritize patching of internet-facing applications and critical vulnerabilities to mitigate risks.
OPSEC Blunder Reveals Global Espionage Campaign Targeting Critical Sectors
An elementary operational security lapse by a state-sponsored threat actor has inadvertently unveiled an extensive global espionage operation. This sophisticated campaign, active since early 2026, has infiltrated diverse targets, including hospitals, government agencies, and educational institutions across multiple continents.
Table Of Content
The exposure occurred in mid-April when the attackers left a staging server openly accessible. This server contained an array of tools, command histories, and pre-configured phishing packages, providing a rare glimpse into their active operations. This critical error brought to light the campaign, now designated as JadeProx, which primarily utilizes a previously undocumented malware loader named TriBack.
Initial targets identified within the campaign include a medical imaging system at a public hospital in Vietnam, the Malaysian Ministry of Foreign Affairs, and several educational websites in Hong Kong. Concurrently, separate but related activities were detected in Honduras, where attackers employed fake Claude software themes to entice victims into executing malicious packages.
Analysts at Group-IB were instrumental in identifying the malware and meticulously tracing the consistent presence of the TriBack loader across every compromised system they analyzed. According to a Group-IB report, TriBack Loader initiates its execution through DLL sideloading. It then decrypts and runs shellcode by leveraging standard Windows callback functions, a technique designed to bypass conventional security detection mechanisms.
The campaign deployed multiple TriBack variants. Two of these variants were observed to drop AdaptixC2 beacons, while another delivered a backdoor known as Beagle. The threat actors also established fraudulent portals on their infrastructure, including one masquerading as a Venezuelan municipal tax system, specifically designed to harvest credentials from unsuspecting visitors.
The geographical distribution of targets, stretching from Southeast Asia to Latin America, aligns with typical patterns associated with China-nexus espionage activities. For instance, a lure tailored for Honduras mimicked an official statement from a prominent local beverage company, directed towards the National Congress.
Threat Actors’ OPSEC Failure Exposes Attack Infrastructure
The adversary’s Alibaba Cloud staging server became accessible due to an unconfigured Python web server with directory listing enabled. This oversight left a wealth of sensitive information exposed, including bash histories, webshell paths, phishing kits, and various post-exploitation tools.
The exposed directories contained critical components such as port forwarders, SOCKS tunnels, network scanners, and scripts intended to obscure the server’s activity from cloud host monitoring systems. Analysis of command logs revealed active tunnels into the Vietnamese hospital’s imaging system and attempts to access Malaysian foreign affairs systems. The victim footprint, as illustrated in Group-IB’s findings, clearly spans both Southeast Asian (SEA) and Latin American (LATAM) regions.
Further examination of these logs demonstrated the actors’ method of delivering DLL sideloading packages to Windows hosts accessed via internal tunnels. A specific archive targeting Honduras was found to utilize a legitimately signed Microsoft host binary to load a malicious DLL, thereby bypassing common security alerts. Similarly, Claude-themed packages exploited other trusted vendor applications through analogous methods across various uploads. Cybersecurity professionals familiar with DLL sideloading techniques will recognize how trusted programs are subverted to discreetly launch subsequent stages of an attack.
TriBack Loader’s Evasion Techniques
TriBack Loader typically consists of a small set of files: a signed legitimate program, a malicious DLL, and an encrypted data file. Following a rapid decryption process that involves byte reversal and a rolling key, the malware executes its code using unconventional Windows callbacks, rather than standard thread creation mechanisms. This design choice enables it to circumvent many endpoint detection products that monitor for typical thread initiation patterns.
Researchers observed four distinct builds of TriBack over approximately two months. While each variant swapped host binaries and callback functions, they consistently maintained the same builder style. Two of these builds deployed AdaptixC2, with researchers successfully recovering full beacon settings, including sleep intervals and HTTP profiles.
A third variant employed shellcode to execute the Beagle backdoor, communicating with domains exhibiting a consistent registration pattern. The continued abuse of open-source frameworks like AdaptixC2 underscores their appeal to threat actors due to their effectiveness and accessibility.
What You Should Do
- Network Blocking: Immediately block all identified malicious domains and IP addresses at the network perimeter and DNS layer.
- Endpoint Hunting: Actively hunt for nested folders named with the pattern “_CL” followed by digits in mail and endpoint logs.
- DLL Sideloading Detection: Configure monitoring to flag signed vendor binaries executing from user-writable paths, especially when a companion data or log file is present in the same directory.
- Startup Folder Review: Regularly review entries in startup folders for suspicious executables or scripts.
- Cleanup Script Detection: Watch for artifacts such as double-extension cleanup scripts (e.g.,
~del.vbs.bat). - Vulnerability Management: Prioritize patching for all internet-facing Java applications and address any unpatched critical vulnerabilities immediately.
- Threat Intelligence Integration: Integrate the provided Indicators of Compromise (IoCs) into your threat intelligence platforms (e.g., MISP, VirusTotal, SIEM) for enhanced detection and correlation.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| IP Address | 43.106.71[.]28:8000 | Exposed operator staging server (Alibaba Cloud Singapore) |
| IP Address | 8.217.190[.]58 | C2 related to license[.]claude-pro[.]com (Alibaba US) |
| IP Address | 104.21.60[.]96 | Cloudflare IP for sylverixstrategy[.]com |
| IP Address | 161.35.236[.]255 | DigitalOcean IP for gouvvbo[.]top |
| IP Address | 178.128.108[.]89 | DigitalOcean IP for vertextrust-advisors[.]com |
| IP Address | 192.252.186[.]62 | C2 for update-trellix[.]com and related update domains |
| Domain | sylverixstrategy[.]com | AdaptixC2 C2 domain (open directory variant) |
| Domain | gouvvbo[.]top | AdaptixC2 C2 domain (Honduras variant) |
| Domain | license[.]claude-pro[.]com | Beagle / Claude-Pro themed variant C2 |
| Domain | claude-pro[.]com | Phishing domain hosting MSI packages |
| Domain | vertextrust-advisors[.]com | Fake advisory portal on campaign infrastructure |
| Domain | update-trellix[.]com | C2 domain used with GolddTV.msi variant |
| Domain | update-crowdstrike[.]com | Related NameSilo-registered update lure domain |
| Domain | update-sentinelone[.]com | Related NameSilo-registered update lure domain |
| Domain | dlrz-web.oss-cn-beijing.aliyuncs[.]com | Alibaba OSS bucket used for staged tools |
| File Hash (MD5) | bb5c88de9e04e6306260b9f3a4498933 | Estado de Cuenta.zip (Honduras lure archive) |
| File Hash (MD5) | 35cdbf8a16da1245d574a0365cb87287 | Estado de Cuenta.lnk |
| File Hash (MD5) | 0e6d22c2a81d29b1f9d8395d44e19e53 | script.vbs |
| File Hash (MD5) | d99392248bdd7e351e63ead6733638ba | hostfxr.dll |
| File Hash (MD5) | df1f03a2534480a4838f62339bcb90d8 | hostfxr.dll |
| File Hash (MD5) | 7840f30b395fac347f85b38633c2d08d | bjh.zip |
| File Hash (MD5) | 9e01bf0e28c86435cfb1afaef44238e9 | ServiceHub.DataWarehouseHost.exe.log |
| File Hash (MD5) | 5222a31cf24f9f57ae3d1831f264a983 | ServiceHub.DataWarehouseHost.exe.dat |
| File Hash (MD5) | fef1d3cb35129ad25d95e279565b9001 | Related Windows payload hash |
| File Hash (MD5) | f2ce6fe8b52dfbacfee482a48f4ae972 | Claude-Pro-Relay-Technical-Overview.zip |
| File Hash (MD5) | 38e317af0fc0efcc88265f243a264542 | suo5-linux-amd64 |
| File Hash (MD5) | 5b75b00a4b4c32b6e213514e80500a65 | Related Linux tool hash |
| File Hash (MD5) | 8002ab4d0cf7e1888ee72de0b9f4282c | linux_amd64 (garbled NPS proxy) |
| File Hash (MD5) | 7c84e75817349adcdea9925b86f67670 | iox |
| File Hash (MD5) | aedd185b76ccda8d65dbd26204cc0e9a | fuckaliyun.sh |
| File Hash (MD5) | f360afe51b499a036c7be8c0ecc4dc89 | neoreg.py |
| File Hash (MD5) | 39d4012e49f58092ec5cefed13dbbcfd | Related toolkit hash |
| File Hash (MD5) | dtdee5a2cdd4ce6ccb2e9279c9e13e8bd15 | nuclei |
| File Hash (MD5) | b8053bcd04ce9d7d19c7f36830a9f26b | fscan / mail.log |
| File Hash (MD5) | 0482d6053f96e6bde0a92af25497f3c0 | socks5-server |
| File Name | Estado de Cuenta.zip | Honduras-themed phishing archive |
| File Name | hostfxr.dll | Malicious DLL sideloaded by signed Microsoft host |
| File Name | avk.dll | Malicious DLL sideloaded via G DATA binary |
| File Name | MpClient.dll | Malicious DLL in DeviceSync variant |
| File Name | ~del.vbs.bat | Self-delete double-extension cleanup artifact |
| File Name | Claude.msi / GolddTV.msi | MSI installers delivering TriBack Loader |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.