An exposed directory on an operator-controlled Alibaba Cloud server revealed the inner workings of the JadeProx intrusion set. Investigators traced concurrent operations targeting a Vietnamese public hospital’s medical imaging system, the Malaysian Ministry of Foreign Affairs, multiple Hong Kong educational institutions, and government entities in Honduras and Venezuela. The open directory showed heavy use of Chinese-origin offensive tooling: iox and Neo-reGeorg for tunneling, suo5 for SOCKS5-over-HTTP pivoting via webshells, nuclei and fscan for mass vulnerability scanning and internal reconnaissance, and a modified fuckaliyun.sh script designed to disable Alibaba Cloud”s security monitoring agents.
The same infrastructure also hosts convincing phishing portals.
One domain impersonates the municipal tax system for the Venezuelan Municipality Piar, collecting identity documents and payment records while doubling as a C2 endpoint for AdaptixC2 beacons. Another front site, “Vertex Trust Advisors,” mimics a Singapore-based financial services brand to provide cover for Claude-Pro themed malware distribution, making backend domains appear more legitimate to reputation systems. TriBack Loader, a three-file triad, abuses DLL sideloading of signed binaries to decrypt and execute shellcode payloads in memory using Win32 callback APIs rather than typical thread creation routines.
Across four identified variants, the operators rotate host binaries (e.g., Microsoft Service Hub, G DATA avk, Microsoft MpClient utilities) while preserving a consistent two-stage decryption pattern based on byte reversal and rolling XOR with per-build keys.
In Hong Kong, a targets list of over 14,000 education-sector URLs was scanned with nuclei using only critical-severity templates, leading to exploitation of CVSS 9.8 vulnerabilities.











