JadeProx is getting in by looking like software people already trust. The danger is not a single malicious file, but the fact that a fake installer or update can carry the first stage past casual review and hand off to follow-on tools from there.
Group-IB tied the campaign to a new Windows loader, TriBack Loader, used against government, healthcare, and education targets across Asia and Latin America. The lures included lookalike vendor-style domains and a fake Claude installer, with multiple builds relying on signed binaries, DLL sideloading, and persistence through normal Windows startup behavior.
That shifts the problem from endpoint filtering alone to the trust model around downloads, installers, and update paths. If those paths are easy to impersonate, the initial foothold can arrive already wrapped in legitimacy.