JadeProx
Essential information
- Confidence
- 100/100
- Published
- 23/07/2026 17:16
- Modified
- 23/07/2026 17:16
- Updated at
- 23/07/2026 17:16
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 15 attack patterns (mitre), 6 malware, 3 sectors, 17 indicators, 4 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (15)
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1071.001 usesWeb Protocols MITRE
-
T1190 usesExploit Public-Facing Application MITRE
-
T1574.001 usesDLL MITRE
-
T1090.001 usesInternal Proxy MITRE
-
T1583.001 usesDomains MITRE
-
T1547.001 usesRegistry Run Keys / Startup Folder MITRE
-
T1036.005 usesMatch Legitimate Resource Name or Location MITRE
-
T1595.002 usesVulnerability Scanning MITRE
-
T1218 usesSystem Binary Proxy Execution MITRE
-
T1059.005 usesVisual Basic MITRE
-
T1573.001 usesSymmetric Cryptography MITRE
Malware (6)
-
PlugX - S0013 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AdaptixC2 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
TriBack Loader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Korplug usesThe MITRE Corporation Confidence 100
[PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: New DragonOK)(Citation:…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Beagle usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
XMRig usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (3)
-
Government targets
-
Education targets
-
Healthcare targets
Indicators (17)
-
stix 100/100 Revoked· Valid until 23/05/2026 · Source: AlienVault
-
stix 100/100· Valid until 19/07/2027 · Source: AlienVault
-
stix 100/100· Valid until 19/07/2027 · Source: AlienVault
-
stix 100/100· Valid until 19/07/2027 · Source: AlienVault
Vulnerabilities (CVE) (4)
Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.
- Published
- 03/11/2021
- Modified
- 23/07/2026
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
- Attack vector
- NETWORK
- Published
- 18/05/2021
- Modified
- 23/07/2026
- EPSS
- 0.1118 (P95.5%)
- Published
- 23/07/2026
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x …
- Attack vector
- NETWORK
- Published
- 18/03/2021
- Modified
- 23/07/2026