Triofox Security Flaw Used to Deploy Malware, Patch Released

12 Nov 2025

A critical security vulnerability in Gladinet Triofox, identified as CVE-2025-12480, has been exploited by hackers to install malware through its remote access tool features. Despite the flaw being fixed on 2025-07-26, the threat continued as attacks persisted, targeting users who had not updated their systems.

Details of the Exploit

The flaw, given a severity score of 9.1 out of 10, was likely introduced in April 2025. It allowed unauthorized access to Triofox's setup pages even after installation was complete. Security teams from Mandiant and Google's Threat Intelligence Group identified the improper access control as the main issue. The vulnerability was exploited by a group known as UNC6485.

  • Triofox vulnerability CVE-2025-12480 identified
  • Faulty access control enabled unauthorized access
  • Attacks reported post July 2025 patch release
  • UNC6485 involved in exploiting the flaw

Impact and Mitigation

A particular incident involved deploying malicious tools Zoho UEMS, Zoho Assist, and AnyDesk for remote access. The attackers utilized Plink and PuTTY for SSH tunneling, allowing lateral movement within the systems. Triofox released a patched version 16.7.10368.56560 on 2025-07-26, and a further updated version 16.10.10408.56683 was made available on 2025-10-14. Users should apply updates immediately to prevent exploitation.

Recommendations for Users

To ensure security, Triofox users are advised to update to the latest version immediately. The vulnerability underscored the importance of timely updates, as attackers took advantage of its presence weeks after the patch was issued. This case serves as a reminder to maintain diligent software management practices.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6472956
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1307043
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
502222
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454987
downloads

News and reviews for Desktop Windows

PC Gaming Show: Most Wanted Nominees Announced by PC Gamer

PC Gamer has unveiled the Most Wanted nominees for The PC Gaming Show, streaming 2023-12-04, showcasing top unreleased games.

Read more

Phasmophobia Opts Out of Live-Service Model

Phasmophobia avoids the live-service model, focusing on fun gameplay over frequent updates.

Read more

Fallout 4 Update Disrupts Mods, Fixes Planned

Fallout 4 Anniversary Edition launch disrupts mods. Bethesda plans multiple fixes by 2025-12-15.

Read more

Emotet Malware Resurges with Enhanced Threats

Emotet malware has re-emerged with new capabilities, posing a threat to global cybersecurity.

Read more

Affordable Office Bundle with Windows 11 Pro and Office 2021 for $49.97

Upgrade to Windows 11 Pro and Office 2021 for $49.97, offering key productivity tools and features at a fraction of the regular price.

Read more

Anno 117 Release Highlights Praise and Criticism

Anno 117: Pax Romana launched on Steam with acclaim for visuals yet faced Denuvo and Ubisoft Connect backlash.

Read more

Arc Raiders Players Avoid PvP on Steam

Arc Raiders players show low engagement in PvP on Steam, with 19% never engaging in combat. Many prefer cooperative achievements.

Read more

PlayStation State of Play Highlights PC and Xbox Games

PlayStation State of Play on 2025-11-11 announced titles for PC and Xbox in 2026, including Elden Ring Nightreign DLC.

Read more

Dragon's Dogma Available in Fanatical's Random Game Bundle

Fanatical offers a $12.99 bundle that may include Dragon's Dogma, enhancing game accessibility.

Read more

Delays Release of Military FPS '83' to 2026

Blue Dot Games delays '83' early access to 2026 for game enhancements.

Read more