CVE Tools
Back to feed
Exploited in the wild TriBack Loader JadeProx malware AdaptixC2 Alibaba Cloud

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

A China-linked cyber operation tracked as JadeProx has deployed a new Windows loader named TriBack Loader to target government, healthcare, and education institutions in Asia and Latin America. The threat actors have leveraged multiple unpatched vulnerabilities including CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, and CVE-2021-32305—each rated with a high CVSS score of 9.8—to gain initial access. Once inside, they used DLL sideloading techniques to execute malicious payloads and deliver post-exploitation tools like AdaptixC2 and Beagle. Sophos and Group-IB have identified spear-phishing campaigns and domain infrastructure linked to the activity, urging organizations to patch exposed Java interfaces and monitor for suspicious file patterns.