Actor Profile

JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore (mid-April 2026). The actor targets government, healthcare, and education organizations across Asia and Latin America. Group-IB stops short of linking JadeProx to an established APT group, noting that tooling circulates freely within the China-nexus ecosystem and tool overlap does not confirm operator identity. The exposed server revealed active intrusions against a Vietnamese public hospital's medical imaging system, Malaysia's Ministry of Foreign Affairs, Hong Kong education infrastructure scanning/exploitation, and spear-phishing against Honduras' National Congress. Operators demonstrate both custom loader development capability and reliance on known critical-severity vulnerabilities dating to 2018–2021.

TTPs (Tactics, Techniques, Procedures)

Initial Access: Spear-phishing with decoy documents (fake beverage account statements, Anthropic Claude impersonation via claude-pro[.]com registered March 28, 2026); exploitation of internet-facing Java management interfaces via webshells; vulnerability scanning with Nuclei (critical-severity templates only) against 14,653 Hong Kong education URLs, exploiting CVE-2018-11511 (ASUSTOR ADM), CVE-2021-24139 (10Web Photo Gallery WordPress plugin), CVE-2021-31755 (Tenda AC11 routers, CISA KEV since Nov 2021), and CVE-2021-32305 (WebSVN), all CVSS 9.8. Execution: DLL sideloading with four TriBack Loader variants pairing legitimate signed executables with malicious DLLs and encrypted .dat/.log payloads; payload decryption via byte reversal and rolling XOR key; shellcode execution through low-visibility Win32 APIs (InitOnceExecuteOnce, TimerQueue callbacks, undocumented EtwpCreateEtwThread in ntdll). Defense Evasion: Signed binary abuse, EDR evasion via non-standard thread-creation routines. Persistence: MSI installer placing sideloading chain in Windows Startup folder. Command and Control: AdaptixC2 (open-source post-exploitation framework), Beagle backdoor (first documented by Sophos) reporting to license[.]claude-pro[.]com. Discovery/Lateral Movement: Post-exploitation tools and webshells recovered from staging server 43.106.71[.]28:8000.

Targets & Patterns

JadeProx targets government, healthcare, and education sectors across Asia (Vietnam, Malaysia, Hong Kong, Singapore, China) and Latin America (Honduras). Confirmed intrusions include a Vietnamese public hospital's medical imaging system (accessed via webshells on exposed Java management interface), Malaysia's Ministry of Foreign Affairs, and scanning/exploitation attempts against Hong Kong education infrastructure (14,653 URLs scanned). A spear-phishing package targeted Honduras' National Congress. The actor prioritizes internet-facing systems with unpatched critical vulnerabilities (CVSS 9.8) and public-facing Java applications. The fake Claude malvertising campaign (claude-pro[.]com) suggests broader targeting beyond government/healthcare, reaching general users searching for legitimate software downloads. The pattern indicates opportunistic exploitation of high-value targets with poor patch management, combined with strategic interest in government foreign affairs and healthcare data.

Historical Context

TriBack Loader is previously undocumented as of the July 23, 2026 Group-IB report. Sophos identified the same reused XOR key in builds dating back to February 2026 but cautioned that shared cryptographic keys alone are insufficient for attribution. The Beagle backdoor was first documented by Sophos in earlier reporting. Group-IB's discovery stems from an exposed Alibaba Cloud server found mid-April 2026 in Singapore's region; the server went offline before the July 23 publication. The custom loader builder's API rotation pattern and four distinct infection chains suggest iterative development through early-to-mid 2026. CVE-2021-31755 (Tenda router flaw) has been on CISA's KEV catalog since November 3, 2021, with federal remediation deadline expired two weeks later, indicating JadeProx exploits years-old unpatched vulnerabilities. The operation represents continued China-nexus activity against regional government and critical infrastructure targets consistent with broader APT trends, though Group-IB does not attribute to a known numbered APT group.

Defensive Recommendations

  • Hunt for DLL sideloading indicators: signed vendor binaries (hostfxr.dll, avk.dll, MpClient.dll) executing from user-writable, temporary, or Startup directories alongside encrypted .dat/.log files, nested _CL_###### folders, or ~del.vbs.bat scripts
  • Block and investigate JadeProx infrastructure: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, update-trellix[.]com, update-crowdstrike[.]com, update-sentinelone[.]com, and staging server 43.106.71[.]28:8000
  • Monitor for low-visibility thread-creation APIs (InitOnceExecuteOnce, TimerQueue callbacks, EtwpCreateEtwThread in ntdll) used for shellcode execution; enhance EDR telemetry for non-CreateThread execution paths
  • Prioritize patching CVE-2018-11511, CVE-2021-24139, CVE-2021-31755 (CISA KEV), and CVE-2021-32305 (all CVSS 9.8); audit internet-facing Java applications and public-facing systems for unpatched critical vulnerabilities
  • Detect malvertising chains: flag MSI installers requesting UAC elevation that drop files to Startup folders; investigate Claude-themed or vendor-impersonation domains registered in March–April 2026 timeframe; monitor for AdaptixC2 and Beagle backdoor IOCs

---

# Geopolitical Context

Geopolitical Context

The JadeProx operation reflects persistent strategic intelligence collection priorities consistent with China-nexus cyber activity. The targeting pattern—government ministries, healthcare infrastructure, and education institutions across Asia and Latin America—aligns with long-term regional influence objectives and information-gathering campaigns. The intrusion into Malaysia's Ministry of Foreign Affairs and Vietnam's public hospital medical imaging systems suggests interest in diplomatic communications and potentially sensitive health data. The Honduras National Congress targeting indicates sustained attention to Latin American legislative and policy developments, consistent with broader Belt and Road engagement strategies. The use of Alibaba Cloud infrastructure in Singapore for command-and-control operations demonstrates continued reliance on regional cloud providers to blend operational traffic with legitimate commercial activity.

State Actor Alignment

Group-IB attributes the activity to a China-nexus threat cluster tracked as JadeProx but explicitly stops short of linking the operation to an established named group, noting that tooling circulates freely within the China-nexus ecosystem. The targeting of foreign ministries, legislative bodies, and critical infrastructure is consistent with state-sponsored intelligence priorities, though the researchers emphasize that shared tools do not constitute proof of unified command. The operation's infrastructure—including an exposed Alibaba Cloud server in Singapore discovered in mid-April 2026—and the systematic targeting of government entities across multiple regions suggest coordination aligned with strategic state interests rather than financially motivated cybercrime. No formal attribution to People's Republic of China state organs has been issued by any government at this time.

Business Impacty pro region

The operation's geographic scope underscores two strategic theaters. In Asia, the confirmed intrusions into Malaysian diplomatic infrastructure and Vietnamese healthcare systems, combined with systematic scanning of 14,653 Hong Kong education-related URLs, point to sustained regional intelligence collection across Southeast Asia and Special Administrative Regions. The Hong Kong education sector scanning—which surfaced 13 unique vulnerabilities—may indicate preparation for follow-on operations or mapping of institutional networks. In Latin America, the spear-phishing package targeting Honduras's National Congress represents continued China-nexus interest in legislative and policy processes within countries engaged in Belt and Road or diplomatic recognition debates. For Europe, the operation offers limited direct impact but reinforces patterns observed in parallel campaigns: exploitation of internet-facing enterprise applications, abuse of trusted cloud infrastructure for C2, and malvertising that places consumer users at risk alongside institutional targets. The fake Anthropic Claude campaign, if confirmed as malvertising, extends exposure beyond government and healthcare to general users seeking AI productivity tools.

Forecast

If JadeProx or related China-nexus clusters continue to rely on years-old critical vulnerabilities (CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, CVE-2021-32305) for initial access, organizations that have not applied patches for CVSS 9.8-rated flaws disclosed between 2018 and 2021 will remain at elevated risk, particularly those operating internet-facing Java applications, ASUSTOR NAS devices, Tenda routers, or vulnerable WordPress plugins. If the TriBack Loader builder continues to evolve—rotating signed binaries, sideloading DLLs, and thread-creation APIs—detection will depend on behavioral indicators (signed vendor binaries in user-writable directories, encrypted .dat/.log companions) rather than static signatures. If the malvertising campaign impersonating Anthropic Claude remains active, consumer and enterprise users searching for legitimate AI tools may inadvertently install the Beagle backdoor, expanding the attack surface beyond traditional espionage targets. If regional cloud providers do not enhance abuse detection for command-and-control infrastructure, Southeast Asian Alibaba Cloud and similar platforms will likely continue to host staging servers for China-nexus operations. Organizations in Asia and Latin America with diplomatic, healthcare, or education sector exposure should prioritize patching the four named CVEs, harden internet-facing management interfaces, and monitor for DLL sideloading chains in temporary and startup directories.