China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Group-IB uncovered an exposed Alibaba Cloud server tied to a China-linked operation dubbed JadeProx, revealing a previously undocumented Windows loader called TriBack that was used against government, healthcare, and education targets across Asia and Latin America, including active intrusions into a Vietnamese hospital’s medical imaging system and Malaysia’s foreign ministry. The loader relies on DLL sideloading across four infection chains, with one variant impersonating a Claude desktop installer to deliver a backdoor that researchers say may have spread through malvertising to ordinary users searching for the app.
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is deploying a new Rust-based backdoor called msaRAT that hijacks a headless Chrome or Edge session to relay command-and-control traffic, using the Chrome DevTools Protocol and a WebRTC connection routed through Twilio and Cloudflare Workers so the attacker’s real server never appears in network traffic. Because the malware never makes a direct outbound connection, its communications blend into ordinary browser activity, making it substantially harder for network defenses to detect.
New Check Point Zero-Day Vulnerability Exploited in the Wild
Check Point has confirmed that a critical authentication bypass flaw in its Security Management and Multi-Domain Management products, tracked as CVE-2026-16232, has been actively exploited against a handful of customers whose management environments were exposed directly to the internet. The flaw lets attackers obtain a login token that grants full administrator access via SmartConsole, and CISA has added it to its Known Exploited Vulnerabilities catalog with a July 25 remediation deadline for federal agencies.
Brazilian Banking Trojan Actively Spreading in Portugal
Researchers at Acronis report that Lampion, a banking Trojan that has targeted Portuguese organizations since 2019, remains active in a new phishing campaign impersonating private-sector entities such as an automotive documentation agency, ultimately deploying a credential-stealing RAT that overlays fake login screens on banking websites. The malware’s longevity reflects Portugal’s linguistic proximity to Brazil’s large cybercrime ecosystem, and a recent industry survey found cyberattacks have become the top-ranked business risk for Portuguese companies for the first time in over a decade.
Months-long breach exposes South Korean diplomats’ personal data
South Korea’s Foreign Ministry disclosed that attackers exploited a zero-day vulnerability to breach the Korea National Diplomatic Academy’s online training platform, compromising usernames, names, emails, and encrypted passwords for roughly 10,000 current and former diplomats and officials over an intrusion window running from April 2025 to February 2026. The ministry took the system offline and waited five months to disclose the breach, citing the sensitivity of diplomatic and security matters, while researchers noted the zero-day tactics resemble those previously linked to North Korean state-backed groups.