Leaky Alibaba Cloud Server Exposes China-Linked Spying Kit Aimed at Hospitals and Governments
Researchers at Group-IB stumbled on a misconfigured server in Singapore that revealed a new Windows loader, TriBack, used against targets across Asia and Latin America.

Key points
- Group-IB found an exposed Alibaba Cloud server in the Singapore region in mid-April 2026 tied to a China-linked spying operation it calls JadeProx.
- The server held a previously unknown Windows loader named TriBack Loader, used to smuggle spying tools onto victim machines.
- Targets included government bodies, hospitals, and universities across Asia and Latin America.
- The server had gone offline by the time Group-IB published its findings.
- No public evidence yet links the campaign to a named Chinese state group, and no CVE is involved: this is a spying operation, not a single software flaw.
A Chinese spying crew left the lights on.
Security company Group-IB says it spotted a misconfigured server sitting on Alibaba Cloud, the Chinese equivalent of Amazon's cloud service, in the middle of April 2026. The server was hosted in Singapore. Inside, researchers found the working files of a hacking group they now track under the name JadeProx.
The group had been quietly breaking into government offices, hospitals, and schools across Asia and Latin America. That detail matters, because the victims are places most of us actually deal with: the office that issues your ID, the clinic that holds your medical notes, the university that stores your child's records.
Who are JadeProx and what were they doing?
JadeProx is the name Group-IB gives to a hacking cluster it links to China. The crew's job appears to be espionage, meaning stealing information rather than demanding a ransom. On the exposed server, researchers found a brand-new tool they have named TriBack Loader.
A loader is the quiet first stage of an attack. Think of it as the delivery driver: it slips onto a Windows computer, checks that no security software is watching, and then pulls down the real spying tool that reads files, keystrokes, or emails. TriBack Loader had not been documented anywhere before this find, which is why it caught the researchers' attention.
The original write-up by The Hacker News describes the loader as previously undocumented, and Group-IB's own timeline suggests the operators had been running it for some time before their server was left facing the open internet.
Who was targeted?
Government, healthcare, and education organisations across Asia and Latin America, according to Group-IB. The report does not name individual victims, which is normal for an active investigation.
Here is what is publicly known so far, laid out plainly.
| Detail | What Group-IB found |
|---|---|
| Server discovered | Mid-April 2026 |
| Hosting provider | Alibaba Cloud, Singapore region |
| Tool exposed | TriBack Loader (new Windows loader) |
| Sectors hit | Government, healthcare, education |
| Regions | Asia and Latin America |
| Status now | Server offline at time of reporting |
Should ordinary people be worried?
Not directly, but indirectly, yes. Spying groups like this one usually want documents and email, not your bank card. The risk to you comes from what they take from the hospital, ministry, or university that holds your data.
If you live in one of the affected regions and receive a notice from a public body about a data incident in the coming months, take it seriously. Watch for unusually well-informed phishing emails, which are fake messages that use real personal details to trick you into clicking a link or handing over a password. That is often how stolen government and healthcare data gets reused.
What about the identity angle?
Loaders like TriBack usually land through a stolen password, a booby-trapped document, or a foothold on a contractor's machine. This is the boring truth of most state-linked intrusions: the fancy custom tool arrives after someone reused a password or approved a login prompt they should not have.
Would multi-factor authentication, meaning a second check such as a code or a tap on your phone, have stopped it? Honestly, sometimes. It would not stop a booby-trapped document opened on a workstation. It would stop a huge share of the credential theft that lets these crews get in through a webmail portal or a VPN, meaning a remote-access gateway staff use to reach work systems from home. On the balance of what we usually see in reports like this, phishing-resistant MFA, using hardware keys or passkeys as set out in the WebAuthn standard, would meaningfully raise the bar for JadeProx's next campaign.
Group-IB says the server is now dark. The people behind it are almost certainly not.



