type: incident ยท created: 2026-07-24 ยท updated: 2026-07-24 ยท tags: [incident, espionage, china, loader, jadeprox, government, healthcare] ยท confidence: medium ยท affected_sectors: [government, healthcare, technology] ยท au_impact: true
China-Nexus JadeProx Uses TriBack Loader
A China-nexus actor tracked as JadeProx has been observed using the TriBack loader in attacks on government and healthcare targets โ part of the broader pattern of Chinese state-aligned espionage leveraging loader/implant chains for initial access and persistence.
| Attribute | Detail |
|---|---|
| Actor (nexus) | JadeProx (China-linked) |
| Implant | TriBack loader |
| Targets | Government and healthcare organisations |
| Source | The Hacker News โ Tier 2/4 |
Note: reporting on this campaign is largely an aggregator item; attribution to a specific unit is incomplete and confidence is held at medium.