China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware

China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware

First seen 23 Jul 2026, 14:54 UTC Techtimesthehackernews.comwww.group-ib.comwww.cisa.govcloud.google.com 87% similarity 75.5

Article Content

Browse articles
ThreatCluster

A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware loader named TriBack Loader. Discovered by Group-IB, the operation was revealed after hackers left an exposed directory on their command server, which detailed their activities. The TriBack Loader utilizes DLL sideloading and targets specific Windows callback APIs to evade detection by endpoint security tools. The attack also involved phishing campaigns impersonating Anthropic's Claude AI software. The exposed server contained various tools and scripts, including a modified version of fuckaliyun.sh, designed to disable Alibaba Cloud's security monitoring. The scope of the attack spans multiple regions, including South-East Asia and Latin America, indicating a broader espionage campaign. The server is no longer active, but the implications of the breaches are significant for the affected organizations.

Key Points: • China-linked hackers breached a Vietnamese hospital and other government entities. • The TriBack Loader malware employs advanced evasion techniques against security tools. • An exposed command server revealed detailed operational tactics and victim targets.

ThreatCluster AI

Timeline

2018-08-16
CVE-2018-11511 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-03-18
CVE-2021-24139 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-05-07
CVE-2021-31755 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-05-18
CVE-2021-32305 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-15
Exposed command server discovered
Group-IB found an exposed directory on an Alibaba Cloud server detailing active cyber operations.
Group-IB
2026-07-23
Group-IB publishes technical breakdown
Group-IB released a detailed analysis of the JadeProx operation, revealing multiple targets and attack methods.
Techtimes

Community

Browse all →