China-nexus hackers exposed after leaving their attack server open

A China-linked espionage crew running simultaneous intrusions across Asia and Latin America blew its own cover by leaving a staging server wide open on the internet. In mid-April 2026, researchers at Group-IB stumbled onto an exposed directory on an operator-controlled Alibaba Cloud box that laid bare the group's entire playbook: hacking tools, command history, webshell paths into victims and staged phishing kits. Group-IB tracks the cluster as JadeProx.

What the open server revealed

The operator had left a Python web server running with directory listing switched on, exposing an active toolkit and a running log of their break-ins. From the command history, Group-IB reconstructed simultaneous intrusions against a Vietnamese public hospital's medical imaging (PACS) system, the Malaysian Ministry of Foreign Affairs and multiple Hong Kong educational institutions, plus parallel targeting of Honduras and a phishing portal impersonating a Venezuelan municipal tax system. The victim list spans South-East Asia and Latin America, regions of recurring Chinese economic and strategic interest.

How they operate

At the center of the campaigns is a custom loader Group-IB calls TriBack Loader, delivered by DLL sideloading and using Win32 callback APIs to decrypt and run shellcode while dodging detection. Different builds rotate which signed host program they abuse and which callback API they use, and they deliver either the AdaptixC2 post-exploitation framework or a backdoor called Beagle. The toolkit recovered from the server reads like a China-nexus greatest-hits list: the iox and Neo-reGeorg tunneling tools, the suo5 SOCKS5-over-HTTP proxy, the fscan and nuclei scanners, and a script named "fuckaliyun" modified to disable Alibaba Cloud's host-monitoring agent so the operators could hide their own rented infrastructure.

Against the Hong Kong education sector the operators fed nuclei a machine-generated list of 14,653 URLs and scanned for critical-severity bugs, then followed up by exploiting old but unpatched flaws such as SQL injection vulnerabilities in a photo-gallery app and a WordPress plugin. One phishing strand even impersonated fake Anthropic Claude software, and separate infrastructure hosted the XMRig cryptocurrency miner and SOCKS5 proxy binaries.

What you should do

Defenders in the targeted regions should hunt for the exposed command-and-control IP 43[.]106[.]71[.]28 and watch for DLL sideloading from unusual signed binaries, a hallmark of TriBack Loader. Because the group leans on internet-facing appliances and years-old CVEs for access, prompt patching of edge devices and web applications remains the most effective defense. JadeProx joins a run of state-aligned operations blending commodity tooling with stealthy loaders, echoing the AI-and-cloud abuse that state-backed groups showed off in June.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions