The record
Written from the 1 report below. Nothing here is unsourced.
- Security firm Group-IB uncovered a China-linked hacking operation, tracked as JadeProx, through an exposed Alibaba Cloud server that revealed its tooling and targets.
- The group used a previously undocumented Windows malware loader called TriBack Loader to attack government, healthcare, and education organizations across Asia and Latin America, including a Vietnamese hospital, Malaysia's Ministry of Foreign Affairs, Hong Kong education infrastructure, and a spear-phishing attempt on Honduras's National Congress.
- The group also ran a fake Claude software download site to distribute malware, and exploited long-known critical vulnerabilities in internet-facing systems.
- The findings matter because the fake software site means ordinary users searching for Claude downloads could also be exposed, not just the targeted organizations.
What to watch next
- Whether more victims or intrusions are identified from the exposed server's contents, especially among the 14,653 scanned Hong Kong education URLs.
- Whether defenders report new infections from the fake Claude site (claude-pro[.]com) or the security-vendor lookalike domains.
- Whether Group-IB or other firms formally attribute JadeProx to a known China-nexus group despite the caveat that shared tools do not confirm shared operators.
Coverage1
1 report
English national1
All filed from India
Named Singapore · Vietnam · Malaysia · Hong Kong SAR China · Honduras · United States · Anthropic · Claude · Hong Kong education infrastructure · Ministry of Foreign Affairs, Malaysia · National Congress of Honduras · Vietnamese public hospital · AdaptixC2 · Alibaba Cloud · Beagle · CISA · Group-IB · JadeProx
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
