A China-Nexus Spy Crew Impersonated Claude, CrowdStrike, and SentinelOne. Its Victims Were a Hospital and a Congress. Here Are the Domains.
- Patrick Duggan
- 2 hours ago
- 4 min read
Group-IB published a report this morning on a China-nexus espionage operation it tracks as JadeProx. The way they found it is the kind of mistake that hands investigators everything: an operator left an Alibaba Cloud server exposed in Singapore, and its bash history, phishing kits, post-exploitation tools, and webshell paths laid the whole campaign out on the table. The server was offline by the time the report went out. The record it left behind was not.
What that record showed is a crew running intrusions against exactly the targets that cannot afford to be a headline: a Vietnamese public hospital's medical imaging system, Malaysia's Ministry of Foreign Affairs, Hong Kong education infrastructure, and a spear-phishing package addressed to the National Congress of Honduras. A hospital, two governments, and a school system. None of them have a CrowdStrike retainer. All of them are exactly who we built the free feed for.
The tell: they dressed up as the tools you trust
Here is the part that made us sit up. JadeProx did not hide its command-and-control behind random gibberish domains. It hid behind the names of the security industry — and behind ours.
The operation staged C2 and lures on claude-pro[.]com and license[.]claude-pro[.]com, delivering a Claude-themed variant of the Beagle backdoor. To be clear about what that is and is not: those are not Anthropic domains. They are lookalikes a threat actor registered to borrow the trust of a name people now associate with a helpful AI assistant. It is the same move AWS pulled when it weaponized the Anthropic name in its own marketing last year, except here it is an espionage crew doing it to plant a backdoor. The Claude name is having its trust spent by people who did not earn it. We are going to keep naming that every time we see it.
They did the same to the defenders. Three of the lure domains are fake security-vendor update servers: update-crowdstrike[.]com, update-sentinelone[.]com, and update-trellix[.]com. The psychology is precise. A user who would never click a strange link will absolutely run something that looks like an endpoint-security update, because the whole point of that software is that you let it change things on your machine. Impersonating the guard is how you get past the guard.
The rest of the infrastructure — sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and a staging server at 43.106.71[.]28 on port 8000 — rounds out a kit built for consultancy-and-government social engineering.
This is the sixth one on Alibaba Cloud
We have been pulling on this thread since April, when we published "The Alibaba Thread: Five Chinese APT Operations, One Cloud Provider" — five separate China-nexus operations we had tied back to Alibaba Cloud infrastructure. JadeProx makes six. The staging server that gave the whole thing away was in Alibaba Cloud's Singapore region. That is not a coincidence you note once; it is a fingerprint you track. When a China-nexus operator needs regional cloud infrastructure that blends into legitimate Asian traffic, this is where a striking number of them keep landing.
What we did with it — and what we did not
Group-IB found this campaign and attributed it. We did not, and we are not going to dress up their work as ours. What we did is the unglamorous, useful part: we pulled every hard indicator out of the report, checked each one against our own index — none of the nine were already in our corpus — noted that the staging IP sits inside the 43.106.0.0/16 range where other feeds already flag Cobalt Strike and Mirai command-and-control, and then wrote all nine into our distributed feed so they flow into the IP and domain blocklists.
That means a hospital IT team in Vietnam, or a legislature's sysadmin in Honduras, can block this campaign's infrastructure tonight without a purchase order and without reading a twenty-page PDF. The indicators are the product. The feed is how they reach the people in this story who cannot pay for threat intelligence.
The defender playbook
Block the nine. claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, update-trellix[.]com, update-crowdstrike[.]com, update-sentinelone[.]com, and 43.106.71[.]28. They are in our feed now; if you pull it, the blocking is done.
Treat any update-<vendor> domain as hostile. Real security-vendor updates do not arrive from update-crowdstrike[.]com. Your endpoint agent updates through the vendor's own management channel, not a public lookalike domain. If you see DNS lookups for these, someone in your environment already clicked.
Patch the boring edge. JadeProx got initial footholds through old, unglamorous N-day flaws — ASUSTOR NAS (CVE-2018-11511), Tenda AC11 routers (CVE-2021-31755), the 10Web Photo Gallery WordPress plugin (CVE-2021-24139), and WebSVN (CVE-2021-32305), all rated 9.8. These are the devices nobody inventories: a NAS in a supply closet, a branch router, a plugin on a forgotten site. A state-aligned crew will walk in through any of them.
Watch the crown-jewel systems. The named victims point at where this crew goes once inside: medical imaging systems, foreign-ministry mail, legislative networks. If you run those, assume you are a target profile and hunt for the Beagle and AdaptixC2 post-exploitation tooling this operation carried.
The point
An espionage crew that has to impersonate Claude and CrowdStrike to get its foot in the door is telling you where the trust lives. The defense is not exotic: know the names your users actually trust, and treat every lookalike of those names as an attack. We put the lookalikes in the feed. Go block them — especially if you are the hospital.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
