A new shellcode loader, dubbed “TriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signed binaries and uncommon Win32 callback APIs. Across at least four observed variants, the…
The post New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs appeared first on IT Security News.
SOCIAL SHARE CARD GENERATOR