Triofox Security Flaw Used to Deploy Malware, Patch Released

12 Nov 2025

A critical security vulnerability in Gladinet Triofox, identified as CVE-2025-12480, has been exploited by hackers to install malware through its remote access tool features. Despite the flaw being fixed on 2025-07-26, the threat continued as attacks persisted, targeting users who had not updated their systems.

Details of the Exploit

The flaw, given a severity score of 9.1 out of 10, was likely introduced in April 2025. It allowed unauthorized access to Triofox's setup pages even after installation was complete. Security teams from Mandiant and Google's Threat Intelligence Group identified the improper access control as the main issue. The vulnerability was exploited by a group known as UNC6485.

  • Triofox vulnerability CVE-2025-12480 identified
  • Faulty access control enabled unauthorized access
  • Attacks reported post July 2025 patch release
  • UNC6485 involved in exploiting the flaw

Impact and Mitigation

A particular incident involved deploying malicious tools Zoho UEMS, Zoho Assist, and AnyDesk for remote access. The attackers utilized Plink and PuTTY for SSH tunneling, allowing lateral movement within the systems. Triofox released a patched version 16.7.10368.56560 on 2025-07-26, and a further updated version 16.10.10408.56683 was made available on 2025-10-14. Users should apply updates immediately to prevent exploitation.

Recommendations for Users

To ensure security, Triofox users are advised to update to the latest version immediately. The vulnerability underscored the importance of timely updates, as attackers took advantage of its presence weeks after the patch was issued. This case serves as a reminder to maintain diligent software management practices.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6463730
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1303974
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
500757
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454842
downloads

News and reviews for Desktop Windows

Dragon's Dogma Available in Fanatical's Random Game Bundle

Fanatical offers a $12.99 bundle that may include Dragon's Dogma, enhancing game accessibility.

Read more

Delays Release of Military FPS '83' to 2026

Blue Dot Games delays '83' early access to 2026 for game enhancements.

Read more

Google Reboots Cameyo for Windows Apps on ChromeOS

Google relaunches Cameyo for seamless Windows app use on ChromeOS, boosting enterprise adoption.

Read more

Bloodlines 2 Winter Update Reveals New Features and Bug Fixes

The Chinese Room announces a roadmap for Bloodlines 2, featuring winter and Valentine's Day updates, new features, and two DLCs for 2026.

Read more

Anno 117 Set for Release November 2025 on PC and Consoles

Anno 117, a narrative-driven city builder, launches on PC and consoles in November 2025, enhancing gameplay for Roman history enthusiasts.

Read more

Bloodlines 2 Roadmap Adds New Features and Fixes

Bloodlines 2 roadmap released: Patch 1.0.5 adds FOV slider and saves, with more updates in 2026.

Read more

Arc Raiders Update Expands with New Map and Features

Arc Raiders' North Line update launches 2025-11-13, adding Stella Montis map, community events, and new enemies.

Read more

Tiny386 Transforms Microcontroller into i386 PC Emulator

Tiny386, created by He Chunhui, enables ESP32-S3 to run Windows 95, expanding microcontroller capabilities.

Read more

Triofox Security Flaw Used to Deploy Malware, Patch Released

A vulnerability in Triofox, exploited before patching, allowed malware deployment. Patch now available; update recommended.

Read more

Escape From Tarkov 1.0 Aims for Hardcore Challenge

Tarkov's 1.0 release in 2023 promises a challenging, hardcore experience, retaining its original identity.

Read more