JadeProx TriBack Campaign An exposed directory on an operator-controlled Alibaba Cloud server revealed the inner workings of the JadeProx intrusion set, including bash history, webshell paths, phishing kits, and a full post-exploitation toolkit. From this single staging host, investigators traced concurrent operations targeting a Vietnamese public hospital’s medical imaging system, the Malaysian Ministry of Foreign Affairs, multiple Hong Kong educational institutions, and government entities in Honduras and Venezuela. The open directory showed heavy use of Chinese-origin offensive tooling: iox and Neo-reGeorg for tunneling, suo5 for SOCKS5-over-HTTP pivoting via webshells, nuclei and fscan for mass vulnerability scanning and internal reconnaissance, and a modified fuckaliyun.sh script designed to disable Alibaba Cloud’s security monitoring agents.
Across four identified variants, operators switch host binaries (e.g., Microsoft Service Hub, G DATA avk.exe, Microsoft MpClient utilities) while maintaining a consistent two-stage decryption pattern based on byte reversal and rolling XOR with per-build keys. The JadeProx victimology map reveals that two variants load AdaptixC2, an open-source beacon framework, with decrypted configurations showing HTTP C2 profiles, sleep intervals, and in one case linking activity to previously documented Chinese APT tooling through a GitHub analytics cookie. Another front site, “Vertex Trust Advisors,” mimics a Singapore-based financial services brand to provide cover for Claude-Pro themed malware distribution, making backend domains appear more legitimate to reputation systems.












