Threat Actor

JadeProx

Properties

summary
A China-nexus intrusion cluster that used an exposed Alibaba Cloud server and a previously undocumented TriBack loader to target government, healthcare, and education sectors.
first_seen
2026-07-27T04:00:26.959997+00:00
last_seen
2026-07-27T04:00:26.959997+00:00
created_at
2026-07-27T04:00:26.959997+00:00
mention_count
1
evidence_url
https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
target
Government, healthcare, and education organizations in Asia and Latin America
provenance
news-scan
suspected_origin
China
scan_confidence
0.85
status
pending

Explore this actor's full graph with Ninja Signal