[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_jp3tW6IfY8eG83cwGXxIznIvJ95dGqPCBzvofVA_dw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"70ed8a2f-3adc-41a8-a05a-f57fc0d3ad69","china-linked-jadeprox-exploits-old-cves-and-phishing-to-hit-government-and-healthcare","a535f90d-d0a4-4f64-b8b1-b1bc849205e3","China-Linked JadeProx Exploits Old CVEs and Phishing to Hit Government and Healthcare","The JadeProx operation succeeded partly because organizations were still exposed to vulnerabilities dating back to 2018 and 2021, demonstrating that unpatched legacy flaws remain a reliable entry point for advanced threat actors. Attackers combined this with phishing campaigns impersonating trusted AI software (Claude\u002FAnthropic) to lower user defenses and gain initial access. Once inside, the TriBack Loader's use of DLL sideloading with rotating Windows APIs allowed it to evade modern EDR solutions, highlighting how sophisticated loaders can render endpoint controls ineffective when underlying hygiene is poor. The exposure of an Alibaba Cloud server by the attackers themselves also underscores that operational security failures can cut both ways — but defenders cannot rely on adversary mistakes to protect critical infrastructure.","**Immediate actions:**\n- Patch CVE-2021-31755 and CVE-2018-11511 immediately on all affected internet-facing systems, prioritizing government and healthcare assets.\n- Audit and harden cloud storage configurations (e.g., Alibaba Cloud, AWS S3) to eliminate publicly exposed buckets or misconfigured servers.\n- Deploy phishing-resistant MFA across all user accounts, especially for email and remote access portals.\n\n**Detection measures:**\n- Enable behavioral detection rules in your EDR\u002FSIEM for DLL sideloading patterns and suspicious use of Windows APIs such as InitOnceExecuteOnce, TimerQueue, and EtwpCreateEtwThread.\n- Implement DNS and network monitoring to flag C2 communication patterns associated with AdaptixC2 and Beagle backdoor indicators of compromise.\n- Ingest and correlate threat intelligence feeds referencing JadeProx\u002FTriBack TTPs mapped to MITRE ATT&CK to proactively hunt for intrusion artifacts.\n\n**Long-term improvements:**\n- Establish a formal vulnerability management program with SLA-based patching timelines (e.g., critical CVEs patched within 15 days) enforced across all asset classes.\n- Conduct regular security awareness training that includes AI software impersonation scenarios to reduce phishing susceptibility among staff.\n- Implement network segmentation to isolate government and healthcare systems, limiting lateral movement opportunities if initial access is achieved.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 7: Continuous Vulnerability Management","CIS Control 9: Email and Web Browser Protections","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 SC-7: Boundary Protection","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","MITRE ATT&CK T1574.002: DLL Side-Loading","MITRE ATT&CK T1566: Phishing","MITRE ATT&CK T1190: Exploit Public-Facing Application","GDPR Article 32: Security of Processing (for healthcare data at risk)","NIST CSF ID.RA-1: Asset Vulnerabilities Identified","published","2026-07-23T16:22:22.708308+00:00","2026-07-23T16:22:22.425+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fchina-nexus-jadeprox-uses-new-triback.html","china-nexus-jadeprox-uses-new-triback-loader-in-government-and-healthcare-attack-fc34db","China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":45,"name":46,"slug":47,"description":48,"color":49},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]