www.group-ib.com
China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware loader named TriBack Loader. Discovered by Group-IB, the operation was revealed after hackers left an exposed directory on their command server, which detailed their activities. The TriBack Loader utilizes DLL sideloading and targets specific Windows callback APIs to evade detection by endpoint security tools. The attack also involved phishing campaigns impersonating Anthropic's Claude AI software. The exposed server contained various tools and scripts, including a modified version of fuckaliyun.sh, designed to disable Alibaba Cloud's security monitoring. The scope of the attack spans multiple regions, including South-East Asia and Latin America, indicating a broader espionage campaign. The server is no longer active, but the implications of the breaches are significant for the affected organizations.
Key Points: • China-linked hackers breached a Vietnamese hospital and other government entities. • The TriBack Loader malware employs advanced evasion techniques against security tools. • An exposed command server revealed detailed operational tactics and victim targets.