Back to Blog
CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, CVE-2021-32305: Multiple Windows CVEs — Critical Loader Exploited in Government Attacks (April 2026)
vulnerabilities

CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, CVE-2021-32305: Multiple Windows CVEs — Critical Loader Exploited in Government Attacks (April 2026)

breachwire TeamJul 24, 20262 min read

CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, CVE-2021-32305 — Microsoft Windows

These four critical Windows vulnerabilities (CVSS 9.8) are being actively exploited by the China-nexus JadeProx group using a new loader, TriBack Loader, to compromise government and healthcare networks. The campaign leverages these CVEs for initial access and privilege escalation, enabling persistent backdoor deployment and lateral movement. Exploitation is ongoing and confirmed in the wild.

Attack Vector

JadeProx operators use spear-phishing and malvertising to deliver TriBack Loader, which exploits the listed CVEs to gain foothold in targeted Windows environments. The loader establishes persistence via DLL sideloading (notably hostfxr.dll, avk.dll, MpClient.dll) and deploys backdoors such as Beagle and AdaptixC2. Webshells and malicious scripts (~del.vbs.bat) are used for further exploitation. Infrastructure includes domains like claude-pro.com, sylverixstrategy.com, and update-trellix.com, with C2 traffic observed to 43.106.71.28:8000.

Who Is at Risk

Organizations running unpatched Windows systems, especially in government, healthcare, and education sectors, are at immediate risk. Confirmed victims include a Vietnamese public hospital (medical imaging systems compromised), Malaysia Ministry of Foreign Affairs, Hong Kong education institutions, and the National Congress of Honduras. Exposure is global, with infrastructure traced to Alibaba Cloud (Singapore region).

Patch & Mitigate

  • Patch: Apply the latest security updates for CVE-2018-11511, CVE-2021-24139, CVE-2021-31755, and CVE-2021-32305 immediately. Microsoft advisories provide patch details.
  • Workaround: Disable DLL sideloading where possible; restrict macro/script execution from untrusted sources.
  • Detect: Monitor for outbound connections to known JadeProx C2 domains/IPs, unusual DLL loads (hostfxr.dll, avk.dll, MpClient.dll), and execution of suspicious scripts (~del.vbs.bat).

MITRE ATT&CK

  • TA0001 — Initial Access: Spear-phishing and malvertising deliver loader and exploit payloads.
  • TA0005 — Defense Evasion: DLL sideloading and webshells enable persistent, stealthy access.
  • TA0007 — Discovery: Post-exploitation tools enumerate network and system details for lateral movement.

Source: https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: