Threats · 53 days ago

Fake Updates Hide Espionage Inside Normal Trust

JadeProx is getting in by looking like software people already trust. The danger is not a single malicious file, but the fact that a fake installer or update can carry the first stage past casual review and hand off to follow-on tools from there.

Group-IB tied the campaign to a new Windows loader, TriBack Loader, used against government, healthcare, and education targets across Asia and Latin America. The lures included lookalike vendor-style domains and a fake Claude installer, with multiple builds relying on signed binaries, DLL sideloading, and persistence through normal Windows startup behavior.

That shifts the problem from endpoint filtering alone to the trust model around downloads, installers, and update paths. If those paths are easy to impersonate, the initial foothold can arrive already wrapped in legitimacy.

CVE-2021-31755

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: an issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. EPSS 87% (100th percentile).

CISA federal remediation date Nov 17 · date passed

CVE-2021-32305

NVD KEV

CVSS 9.8 CRITICAL: webSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search… EPSS 87% (100th percentile).

CVE-2018-11511

NVD KEV

CVSS 9.8 CRITICAL: the tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection… EPSS 11% (96th percentile).

CVE-2021-24139

NVD KEV

CVSS 9.8 CRITICAL: unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL… EPSS 6% (92nd percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-07-24

Editions

Related stories