SYS::ONLINE
Wasteland.
Briefs1507
Issues20
SinceFeb 2026
LIVE
▣ Breach CHINA-NEXUS-MALWAR 2026-07-23

Vietnamese Hospital, Malaysian Foreign Ministry, Honduran Congress: JadeProx Espionage Campaign

"A China-linked espionage cluster tracked as JadeProx compromised a Vietnamese public hospital's X-ray and MRI imaging system, tunneled through Malaysia's Ministry of Foreign Affairs network, and delivered phishing…"

A China-linked espionage cluster tracked as JadeProx compromised a Vietnamese public hospital's X-ray and MRI imaging system, tunneled through Malaysia's Ministry of Foreign Affairs network, and delivered phishing malware to Honduras's National Congress, all with a previously undocumented custom Windows loader that slipped past major EDR products. The findings come from Group-IB's full technical breakdown published on July 23, 2026, an investigation that broke open only because the operators forgot to disable directory listings on their own command server.

What Happened

Group-IB discovered the operation in mid-April 2026 after locating an exposed staging server at IP address 43.106.71[.]28, hosted in Alibaba Cloud's Singapore region. A Python HTTP server had been left running on port 8000 with directory listing enabled, exposing the folder contents to anyone who found the address.

The open directory was unusually complete. The server's bash command history documented an active campaign in step-by-step detail: tunneling commands aimed at a Vietnamese hospital's Picture Archiving and Communications System (PACS), multiple intrusion sessions against Malaysia's Ministry of Foreign Affairs, a bulk vulnerability scan of 14,653 Hong Kong education-sector URLs, and a completed phishing archive addressed to Honduras's National Congress. The operators' full toolkit was also present, including tunneling utilities iox, suo5, and Neo-reGeorg.

The central tool in the chain is what Group-IB calls TriBack Loader, a custom Windows loader that cycles through four distinct Windows callback APIs. Those APIs were deliberately chosen because standard EDR products do not instrument them as closely as they monitor more common thread-creation calls, meaning even organizations running modern endpoint protection may never have flagged the infections.

What Was Taken

Group-IB's report documents active intrusion attempts and staged access rather than a fully enumerated data haul, but the exposure is severe by category. The Vietnamese hospital target was its PACS, the infrastructure that stores and distributes patient X-rays, CT scans, and MRI images across a hospital's clinical network, placing sensitive diagnostic and patient imaging data directly at risk.

At Malaysia's Ministry of Foreign Affairs, the command history recorded multiple tunneling sessions, indicating repeated, sustained access to a diplomatic government network, a classic espionage collection target. The Honduras National Congress operation reached the delivery stage: a completed phishing archive was addressed and prepared for the legislature. The Hong Kong education sector saw reconnaissance at scale, with 14,653 URLs run through a bulk vulnerability scan to map exploitable entry points.

Why It Matters

This campaign collapses the usual distinction between nation-state espionage targets and ordinary consumers. The same malware chain that reached a hospital's diagnostic imaging systems also appeared on a phishing website impersonating Anthropic's Claude AI product at the domain claude-pro.com, registered March 28, 2026. Sophos, investigating the fake Claude site independently, assessed it was likely part of an active malvertising campaign, potentially served as a paid sponsored result to anyone searching for Claude AI downloads since late March 2026. Any consumer who downloaded that fake installer would have received the identical tool chain used against government and healthcare networks.

The targeting of a hospital PACS is also a reminder that medical imaging infrastructure is soft, high-value, and often overlooked in security programs. Compromise there threatens patient privacy, diagnostic integrity, and, in a worst case, clinical continuity. Finally, the EDR-evasion approach at the heart of TriBack Loader shows that attackers are now selecting execution primitives specifically for the blind spots in detection tooling, not just for functionality.

The Attack Technique

TriBack Loader executes payloads by rotating through four Windows callback APIs rather than relying on conventional thread-creation calls such as CreateThread or CreateRemoteThread. Because EDR vendors instrument those callback mechanisms less aggressively, the loader can trigger code execution while generating little of the telemetry defenders typically alert on.

Once resident, the operators leaned on off-the-shelf tunneling and proxying tools, iox, suo5, and Neo-reGeorg, to pivot deeper into victim networks and maintain access. Initial delivery in the consumer-facing arm of the campaign came through malvertising and a lookalike domain (claude-pro.com) impersonating a trusted AI product, exploiting search-driven download behavior. The operational security failure that exposed everything was mundane: an internet-facing Python HTTP server on port 8000 with directory listing left enabled, leaking the campaign's bash history, tooling, and staged phishing artifacts.

What Organizations Should Do

Sources: China-Nexus Hackers Breached Hospital X-Rays, Embassy, and Congress With New Malware Loader