TGViewer
Group-IB Group-IB @group_ib · 2.52K subscribers
Post #977 999
🚨A single OPSEC mistake exposed an entire China-nexus operation.

An exposed Alibaba Cloud staging server provided a rare view into an active threat operation. The infrastructure revealed attacker tooling, bash history, victim paths, and post-exploitation activity, leading to the discovery of a previously undocumented threat cluster we track as JadeProx.

Key Highlights:
🔹Discovery of TriBack Loader, a previously undocumented malware family observed across four infection chains.
🔹Targeting of government, healthcare, and education organizations across Southeast Asia, alongside phishing campaigns in Latin America.
🔹Abuse of signed Microsoft and G DATA binaries for DLL sideloading and payload execution.
🔹Use of InitOnceExecuteOnce, TimerQueue callbacks, and EtwpCreateEtwThread for evasion.
🔹Deployment of AdaptixC2 and the Beagle backdoor through a shared loader architecture.
🔹Large-scale vulnerability scanning, credential harvesting, and tunneling activity.

🔗 Read the full blog

#ThreatIntelligence
  • 🔥 8
  • 👍 2
More from @group_ib
  1. Sep 23, 2026🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android bankin…
  2. Sep 17, 2026🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CR…
  3. Sep 14, 2026🚨 Inside the Smishing Triad’s Phishing Cockpit Group-IB’s latest research dives into JWR,…
  4. Sep 9, 2026🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelte…
  5. Sep 3, 2026🚨 Outsider Phishing Kit: a resilient PhaaS threat Group-IB researchers uncovered the Outs…
  6. Sep 1, 2026🚨 Cybercrime is evolving, and so is the underground economy behind it. Group-IB has uncov…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →