TriBack Loader is a previously undocumented Windows loader used by the JadeProx operation. It employs DLL sideloading with four infection chains, using Win32 calls like InitOnceExecuteOnce, TimerQueue callback, and EtwpCreateEtwThread to execute shellcode.