A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort.
It reached hospitals, government offices, and schools across several continents in early 2026. In mid April, operators left a staging server open with tools, command history, and phishing packages ready.
That slip exposed an active campaign now tracked as JadeProx, centered on a newly identified loader called TriBack.
The campaign hit a Vietnamese public hospital medical imaging system, the Malaysian Ministry of Foreign Affairs, and several Hong Kong education sites at once.
Parallel activity also reached Honduras and used fake Claude software themes to lure victims into opening staged packages.
Analysts from Group-IB identified the malware and mapped how the same loader appeared in every infection chain they reviewed.
Group-IB said in a report shared with Cyber Security News (CSN) that TriBack Loader starts through DLL sideloading. It decrypts and runs shellcode using everyday Windows callback functions so security tools are less likely to notice the launch.
Two variants drop AdaptixC2 beacons, while another delivers a backdoor tracked as Beagle. Fake portals, including one posing as a Venezuelan municipal tax system, ran on campaign infrastructure to steal credentials from visitors.
Targets stretched from South East Asia into Latin America, matching patterns often seen in China nexus spying. Honduras received a lure styled as a major local beverage company statement sent toward its National Congress.
Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign
The operators exposed their Alibaba Cloud staging box by leaving a Python web server with directory listing turned on.
The host held bash history, webshell paths, phishing kits, and post exploitation tools in plain view.
.webp)
Inside the open folder sat port forwarders, SOCKS tunnels, network scanners, and scripts meant to hide the server from cloud host monitoring.
Command logs showed tunnels into the Vietnamese hospital imaging system and access attempts against Malaysian foreign affairs systems. Figure 2 maps the victim footprint spanning SEA and LATAM regions.
Those same logs revealed how the actors served DLL sideloading packages to Windows hosts reached through internal tunnels. A related archive aimed at Honduras used a signed Microsoft host binary to load a malicious DLL without easy alerts.
Claude themed packages abused other trusted vendor programs in a similar way across uploads. Teams tracking DLL side loading methods will recognize how trusted programs were twisted to start the next stage quietly.
How TriBack Loader Evades Defenses
TriBack Loader arrives as a small set of files, a signed program, a malicious DLL, and an encrypted data file. After a short decrypt step that reverses bytes and applies a rolling key, the code runs through unusual Windows callbacks instead of common thread starts.
That design helps it slip past many endpoint products that watch for ordinary thread creation patterns on workstations. Four builds appeared across roughly two months, each swapping host binaries and callback choices while keeping the same builder style.
Two of them delivered AdaptixC2 with full beacon settings recovered by researchers, including sleep times and HTTP profiles.
.webp)
A third path used shellcode to run Beagle and talked to domains that followed the same registration pattern. Related coverage of open source AdaptixC2 abuse shows why this framework keeps attracting operators.
Defenders should block listed domains and addresses at the edge and DNS layer. They should also hunt for nested folders named like underscore CL followed by digits in mail and endpoint logs.
Flag signed vendor binaries that launch from user writable paths when a companion data or log file sits nearby. Review Startup folder entries, watch for a double extension cleanup script, and prioritize fixes for internet facing Java apps plus unpatched critical flaws.
Broader Chinese APT campaign activity often shares loaders and tunnel tools, so TriBack keys remain strong hunting anchors.
Guidance on network hunting mitigation steps can help teams apply these findings.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP Address | 43.106.71[.]28:8000 | Exposed operator staging server (Alibaba Cloud Singapore) |
| IP Address | 8.217.190[.]58 | C2 related to license[.]claude-pro[.]com (Alibaba US) |
| IP Address | 104.21.60[.]96 | Cloudflare IP for sylverixstrategy[.]com |
| IP Address | 161.35.236[.]255 | DigitalOcean IP for gouvvbo[.]top |
| IP Address | 178.128.108[.]89 | DigitalOcean IP for vertextrust-advisors[.]com |
| IP Address | 192.252.186[.]62 | C2 for update-trellix[.]com and related update domains |
| Domain | sylverixstrategy[.]com | AdaptixC2 C2 domain (open directory variant) |
| Domain | gouvvbo[.]top | AdaptixC2 C2 domain (Honduras variant) |
| Domain | license[.]claude-pro[.]com | Beagle / Claude-Pro themed variant C2 |
| Domain | claude-pro[.]com | Phishing domain hosting MSI packages |
| Domain | vertextrust-advisors[.]com | Fake advisory portal on campaign infrastructure |
| Domain | update-trellix[.]com | C2 domain used with GolddTV.msi variant |
| Domain | update-crowdstrike[.]com | Related NameSilo-registered update lure domain |
| Domain | update-sentinelone[.]com | Related NameSilo-registered update lure domain |
| Domain | dlrz-web.oss-cn-beijing.aliyuncs[.]com | Alibaba OSS bucket used for staged tools |
| File Hash (MD5) | bb5c88de9e04e6306260b9f3a4498933 | Estado de Cuenta.zip (Honduras lure archive) |
| File Hash (MD5) | 35cdbf8a16da1245d574a0365cb87287 | Estado de Cuenta.lnk |
| File Hash (MD5) | 0e6d22c2a81d29b1f9d8395d44e19e53 | script.vbs |
| File Hash (MD5) | d99392248bdd7e351e63ead6733638ba | hostfxr.dll |
| File Hash (MD5) | df1f03a2534480a4838f62339bcb90d8 | hostfxr.dll |
| File Hash (MD5) | 7840f30b395fac347f85b38633c2d08d | bjh.zip |
| File Hash (MD5) | 9e01bf0e28c86435cfb1afaef44238e9 | ServiceHub.DataWarehouseHost.exe.log |
| File Hash (MD5) | 5222a31cf24f9f57ae3d1831f264a983 | ServiceHub.DataWarehouseHost.exe.dat |
| File Hash (MD5) | fef1d3cb35129ad25d95e279565b9001 | Related Windows payload hash |
| File Hash (MD5) | f2ce6fe8b52dfbacfee482a48f4ae972 | Claude-Pro-Relay-Technical-Overview.zip |
| File Hash (MD5) | 38e317af0fc0efcc88265f243a264542 | suo5-linux-amd64 |
| File Hash (MD5) | 5b75b00a4b4c32b6e213514e80500a65 | Related Linux tool hash |
| File Hash (MD5) | 8002ab4d0cf7e1888ee72de0b9f4282c | linux_amd64 (garbled NPS proxy) |
| File Hash (MD5) | 7c84e75817349adcdea9925b86f67670 | iox |
| File Hash (MD5) | aedd185b76ccda8d65dbd26204cc0e9a | fuckaliyun.sh |
| File Hash (MD5) | f360afe51b499a036c7be8c0ecc4dc89 | neoreg.py |
| File Hash (MD5) | 39d4012e49f58092ec5cefed13dbbcfd | Related toolkit hash |
| File Hash (MD5) | dtdee5a2cdd4ce6ccb2e9279c9e13e8bd15 | nuclei |
| File Hash (MD5) | b8053bcd04ce9d7d19c7f36830a9f26b | fscan / mail.log |
| File Hash (MD5) | 0482d6053f96e6bde0a92af25497f3c0 | socks5-server |
| File Name | Estado de Cuenta.zip | Honduras-themed phishing archive |
| File Name | hostfxr.dll | Malicious DLL sideloaded by signed Microsoft host |
| File Name | avk.dll | Malicious DLL sideloaded via G DATA binary |
| File Name | MpClient.dll | Malicious DLL in DeviceSync variant |
| File Name | ~del.vbs.bat | Self-delete double-extension cleanup artifact |
| File Name | Claude.msi / GolddTV.msi | MSI installers delivering TriBack Loader |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.
The post Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware appeared first on Cyber Security News.
