Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware

A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort.

It reached hospitals, government offices, and schools across several continents in early 2026. In mid April, operators left a staging server open with tools, command history, and phishing packages ready.

That slip exposed an active campaign now tracked as JadeProx, centered on a newly identified loader called TriBack.

The campaign hit a Vietnamese public hospital medical imaging system, the Malaysian Ministry of Foreign Affairs, and several Hong Kong education sites at once.

Parallel activity also reached Honduras and used fake Claude software themes to lure victims into opening staged packages.

Analysts from Group-IB identified the malware and mapped how the same loader appeared in every infection chain they reviewed.

Group-IB said in a report shared with Cyber Security News (CSN) that TriBack Loader starts through DLL sideloading. It decrypts and runs shellcode using everyday Windows callback functions so security tools are less likely to notice the launch.

Two variants drop AdaptixC2 beacons, while another delivers a backdoor tracked as Beagle. Fake portals, including one posing as a Venezuelan municipal tax system, ran on campaign infrastructure to steal credentials from visitors.

Targets stretched from South East Asia into Latin America, matching patterns often seen in China nexus spying. Honduras received a lure styled as a major local beverage company statement sent toward its National Congress.

Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign

The operators exposed their Alibaba Cloud staging box by leaving a Python web server with directory listing turned on.

The host held bash history, webshell paths, phishing kits, and post exploitation tools in plain view.

Attack Chain and Infrastructure (Source - Group-IB)
Attack Chain and Infrastructure (Source – Group-IB)

Inside the open folder sat port forwarders, SOCKS tunnels, network scanners, and scripts meant to hide the server from cloud host monitoring.

Command logs showed tunnels into the Vietnamese hospital imaging system and access attempts against Malaysian foreign affairs systems. Figure 2 maps the victim footprint spanning SEA and LATAM regions.

Those same logs revealed how the actors served DLL sideloading packages to Windows hosts reached through internal tunnels. A related archive aimed at Honduras used a signed Microsoft host binary to load a malicious DLL without easy alerts.

Claude themed packages abused other trusted vendor programs in a similar way across uploads. Teams tracking DLL side loading methods will recognize how trusted programs were twisted to start the next stage quietly.

How TriBack Loader Evades Defenses

TriBack Loader arrives as a small set of files, a signed program, a malicious DLL, and an encrypted data file. After a short decrypt step that reverses bytes and applies a rolling key, the code runs through unusual Windows callbacks instead of common thread starts.

That design helps it slip past many endpoint products that watch for ordinary thread creation patterns on workstations. Four builds appeared across roughly two months, each swapping host binaries and callback choices while keeping the same builder style.

Two of them delivered AdaptixC2 with full beacon settings recovered by researchers, including sleep times and HTTP profiles.

JadeProx victimology map (Source – Group-IB)

A third path used shellcode to run Beagle and talked to domains that followed the same registration pattern. Related coverage of open source AdaptixC2 abuse shows why this framework keeps attracting operators.

Defenders should block listed domains and addresses at the edge and DNS layer. They should also hunt for nested folders named like underscore CL followed by digits in mail and endpoint logs.

Flag signed vendor binaries that launch from user writable paths when a companion data or log file sits nearby. Review Startup folder entries, watch for a double extension cleanup script, and prioritize fixes for internet facing Java apps plus unpatched critical flaws.

Broader Chinese APT campaign activity often shares loaders and tunnel tools, so TriBack keys remain strong hunting anchors.

Guidance on network hunting mitigation steps can help teams apply these findings.

Indicators of Compromise (IoCs):-

Type Indicator Description
IP Address 43.106.71[.]28:8000 Exposed operator staging server (Alibaba Cloud Singapore)
IP Address 8.217.190[.]58 C2 related to license[.]claude-pro[.]com (Alibaba US)
IP Address 104.21.60[.]96 Cloudflare IP for sylverixstrategy[.]com
IP Address 161.35.236[.]255 DigitalOcean IP for gouvvbo[.]top
IP Address 178.128.108[.]89 DigitalOcean IP for vertextrust-advisors[.]com
IP Address 192.252.186[.]62 C2 for update-trellix[.]com and related update domains
Domain sylverixstrategy[.]com AdaptixC2 C2 domain (open directory variant)
Domain gouvvbo[.]top AdaptixC2 C2 domain (Honduras variant)
Domain license[.]claude-pro[.]com Beagle / Claude-Pro themed variant C2
Domain claude-pro[.]com Phishing domain hosting MSI packages
Domain vertextrust-advisors[.]com Fake advisory portal on campaign infrastructure
Domain update-trellix[.]com C2 domain used with GolddTV.msi variant
Domain update-crowdstrike[.]com Related NameSilo-registered update lure domain
Domain update-sentinelone[.]com Related NameSilo-registered update lure domain
Domain dlrz-web.oss-cn-beijing.aliyuncs[.]com Alibaba OSS bucket used for staged tools
File Hash (MD5) bb5c88de9e04e6306260b9f3a4498933 Estado de Cuenta.zip (Honduras lure archive)
File Hash (MD5) 35cdbf8a16da1245d574a0365cb87287 Estado de Cuenta.lnk
File Hash (MD5) 0e6d22c2a81d29b1f9d8395d44e19e53 script.vbs
File Hash (MD5) d99392248bdd7e351e63ead6733638ba hostfxr.dll
File Hash (MD5) df1f03a2534480a4838f62339bcb90d8 hostfxr.dll
File Hash (MD5) 7840f30b395fac347f85b38633c2d08d bjh.zip
File Hash (MD5) 9e01bf0e28c86435cfb1afaef44238e9 ServiceHub.DataWarehouseHost.exe.log
File Hash (MD5) 5222a31cf24f9f57ae3d1831f264a983 ServiceHub.DataWarehouseHost.exe.dat
File Hash (MD5) fef1d3cb35129ad25d95e279565b9001 Related Windows payload hash
File Hash (MD5) f2ce6fe8b52dfbacfee482a48f4ae972 Claude-Pro-Relay-Technical-Overview.zip
File Hash (MD5) 38e317af0fc0efcc88265f243a264542 suo5-linux-amd64
File Hash (MD5) 5b75b00a4b4c32b6e213514e80500a65 Related Linux tool hash
File Hash (MD5) 8002ab4d0cf7e1888ee72de0b9f4282c linux_amd64 (garbled NPS proxy)
File Hash (MD5) 7c84e75817349adcdea9925b86f67670 iox
File Hash (MD5) aedd185b76ccda8d65dbd26204cc0e9a fuckaliyun.sh
File Hash (MD5) f360afe51b499a036c7be8c0ecc4dc89 neoreg.py
File Hash (MD5) 39d4012e49f58092ec5cefed13dbbcfd Related toolkit hash
File Hash (MD5) dtdee5a2cdd4ce6ccb2e9279c9e13e8bd15 nuclei
File Hash (MD5) b8053bcd04ce9d7d19c7f36830a9f26b fscan / mail.log
File Hash (MD5) 0482d6053f96e6bde0a92af25497f3c0 socks5-server
File Name Estado de Cuenta.zip Honduras-themed phishing archive
File Name hostfxr.dll Malicious DLL sideloaded by signed Microsoft host
File Name avk.dll Malicious DLL sideloaded via G DATA binary
File Name MpClient.dll Malicious DLL in DeviceSync variant
File Name ~del.vbs.bat Self-delete double-extension cleanup artifact
File Name Claude.msi / GolddTV.msi MSI installers delivering TriBack Loader

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

The post Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware appeared first on Cyber Security News.