China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Article summary
Quick briefing — cleaned from the original RSS feed
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report
1Key Takeaways
- An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx.
- The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.
- Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report.
2AIWedia Score
8.2/10
High relevance — worth your attention today
Based on source trust, recency, category impact, and story depth.
3Why it matters
Cloud AI updates influence enterprise budgets, latency, and which stack teams standardize on. The Hacker News reports that an exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx.
Explore related
Browse toolsCloud AI news
Explore curated cloud ai tools on AIWedia — compare, rank, and launch from our directory.
Full story on The Hacker News
Read full articleHeadlines aggregated via RSS for discovery on AIWedia. Original content © The Hacker News. We link to the source and do not republish full articles.