An exposed Alibaba Cloud server has revealed a China-nexus
operation that Group-IB tracks as JadeProx. The cluster has
targeted government, healthcare, and education organizations across
Asia and Latin America with a previously undocumented Windows
loader called TriBack Loader. Group-IB found the server in
mid-April 2026 in Alibaba Cloud's Singapore region; it was offline
by the time the report
Read more https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html

