🚨A single OPSEC mistake exposed an entire China-nexus operation.
An exposed Alibaba Cloud staging server provided a rare view into an active threat operation. The infrastructure revealed attacker tooling, bash history, victim paths, and post-exploitation activity, leading to the discovery of a previously undocumented threat cluster we track as JadeProx.
Key Highlights:
🔹Discovery of TriBack Loader, a previously undocumented malware family observed across four infection chains.
🔹Targeting of government, healthcare, and education organizations across Southeast Asia, alongside phishing campaigns in Latin America.
🔹Abuse of signed Microsoft and G DATA binaries for DLL sideloading and payload execution.
🔹Use of InitOnceExecuteOnce, TimerQueue callbacks, and EtwpCreateEtwThread for evasion.
🔹Deployment of AdaptixC2 and the Beagle backdoor through a shared loader architecture.
🔹Large-scale vulnerability scanning, credential harvesting, and tunneling activity.
🔗
Read the full blog
#ThreatIntelligence