An Open Directory and a SEA of Victims: Tracing a China-Nexus Operation Through an OPSEC Mistake - Cybersecurity Conference

An Open Directory and a SEA of Victims: Tracing a China-Nexus Operation Through an OPSEC Mistake

During monitoring of malicious infrastructure, we identified an exposed directory on an operator-owned Alibaba Cloud server that gave us a complete view into an active China-nexus operation tracked as JadeProx. The investigation uncovered simultaneous intrusions against a Vietnamese public hospital’s medical imaging system, the alaysian Ministry of Foreign Affairs, and multiple Hong Kong educational institutions. Running in parallel, similar targeting of Honduras and Venezuela along with phishing campaigns focusing not only in LATAM but themed around fake Anthropic Claude software were observed.

At the centre of all these campaigns is a shellcode loader we track as TriBack Loader, a DLL sideloading technique that decrypts and executes payloads using Win32 callback APIs to avoid detection. Two variants deliver AdaptixC2, a third variant delivers Beagle, a backdoor documented recently and all the domains registered under the same entity. Phishing pages mimicking a municipality of Venezuela among other fake portals have been identified as well. We track this cluster as JadeProx with TTPs overlapping with multiple PRC-nexus groups.

In this talk, we are going to explore all the variants of TriBack Loader observed across different campaigns targeting South East Asia and Latin America, along with their execution timeline from bash history with various Chinese-origin offensive tools like iox, suo5, Neo-reGeorg, nuclei, fscan, fuckaliyun, socks5-server, XMRig proxy, and NPS. We will look into how this directory led us to additional campaigns with new TTPs and overlapping infrastructure using NameSilo domains and Alibaba IPs. A detailed overlap of both tools and loaders with Chinese APTs such as Mustang Panda, Tropic Trooper and more will be showcased along with MSI based stagers and fake phishing portals.

Sathwik Ram Prakki – Group-IB

Sathwik Ram Prakki is a Senior Threat Intelligence Researcher at Group-IB. His areas of research are threat intelligence, APT hunting, delving into dark web and malware analysis. With a background in offensive security and knowledge of OS internals, he is keen on enhancing detections and infrastructure for threat hunting and CTI. Starting his cybersecurity career at C-DAC, under the Ministry of Electronics & IT in India, he has previously worked at Seqrite Labs of Quick Heal and shared insights on APTs, ransomware, malware ecosystems and their infrastructure at international conferences such as AVAR, BlueHat, Botconf, c0c0n, FIRSTCON, SINCON and Virus Bulletin