China-nexus hackers breached hospital X-rays, embassy and Honduran congress with new malware loader
A China-linked espionage operation compromised a Vietnamese public hospital’s X-ray and MRI imaging system, tunneled through Malaysia’s Ministry of Foreign Affairs network, and sent malware to Honduras’s National Congress — all using a custom Windows loader that none of the major endpoint security vendors had previously documented, according to Group-IB’s full technical breakdown published on July 23, 2026. Cybersecurity firm Group-IB stumbled onto the operation through an unusual stroke of luck: the hackers forgot to disable directory listings on their own command server.
The cluster, which Group-IB tracks as JadeProx, used a loader it calls TriBack Loader — a tool that cycles through four distinct Windows callback APIs specifically chosen because standard endpoint detection and response (EDR) products don’t instrument them as closely as they do more common thread-creation calls. The practical result is that even organizations running modern EDR tools may not have flagged the infections.
There is a direct consumer dimension here that extends well beyond the governments and hospitals targeted. The same malware chain appeared on a phishing website impersonating Anthropic’s Claude AI product at the domain claude-pro.com, registered March 28, 2026. Sophos, which investigated the fake Claude site independently, assessed that it was likely part of an active malvertising campaign — meaning it may have been served as a paid sponsored result to anyone searching for Claude AI software downloads since late March 2026. The malware that a user would have downloaded from that link is the same tool chain that penetrated a hospital’s diagnostic imaging infrastructure.
Read more at Tech Times