An exposed directory on an operator-controlled Alibaba Cloud server revealed the inner workings of the JadeProx intrusion set, including bash history, webshell paths, phishing kits, and a full post-exploitation toolkit. From this single staging host, investigators traced concurrent operations targeting a Vietnamese public hospital’s medical...