Vulnerability Patched in Triofox Platform Exploited by Hackers

11 Nov 2025

Mandiant Threat Defense has revealed exploitation of a critical vulnerability in Gladinet's Triofox platform, tracked as CVE-2025-12480.

Timeline and Actions

The flaw, with a CVSS score of 9.1, allowed unauthorized access to Triofox's configuration pages. Attackers used this access to upload and execute arbitrary data by creating a native admin account named Cluster Admin. Mandiant observed these activities by threat cluster UNC6485 starting from 2025-08-24.

  • Triofox users were vulnerable starting 2025-08-24.
  • Exploit allowed attackers to execute malicious files as SYSTEM.
  • Exploitation included deploying Zoho Assist and AnyDesk for deeper intrusion.
  • Actions recommended: update Triofox, audit admin accounts.

Exploitation Details

Attackers configured the antivirus scanner to a malicious script named "centre_report.bat." This script downloaded Zoho UEMS installer files from 84.200.80.252 to support remote access via tools like Zoho Assist, enabling reconnaissance and privilege escalation efforts. Additional tools such as Plink and PuTTY were employed to establish SSH tunnels over port 443, facilitating inbound Remote Desktop Protocol (RDP) access.

Mandiant advises clients to update Triofox to the latest version, carefully audit administrator accounts, and ensure the antivirus settings prohibit unauthorized script execution.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6974975
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1523262
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
642863
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
475975
downloads

News and reviews for Desktop Windows

New Steam Games: Indie Gems You Might Have Missed

Discover unique indie Steam games like Mon Bazou and Swordhaven released recently.

Read more

Com2uS Announces Gachiakuta RPG for Consoles and PC

Com2uS unveils Gachiakuta: The Game for PS5, Xbox, and Steam with unique gameplay inspired by the popular manga and anime.

Read more

Free Steam Offer for The Deed: Dynasty Ends 2023-12-25

The Deed: Dynasty is available for free until December 25 on Steam. Add to your library to keep permanently.

Read more

Offer Ensures Free Rat Quest on Steam Until Christmas

Rat Quest, a platformer on Steam, is free to download until Christmas, offering in-game purchases and future updates.

Read more

Steam Deck Users See Major Discounts in Steam Winter Sale

Steam Winter Sale offers discounts on games for Steam Deck, enhancing gaming options at reduced prices.

Read more

Nightreign's Innovative Twist on Multiplayer Gaming

Nightreign offers multiplayer roguelike challenges with familiar Elden Ring elements, rewards fans with strategic depth.

Read more

Deepwoken Dominates RPG Searches on Roblox in 2025

PC gaming trends in 2025 show a preference for Deepwoken, a hardcore RPG on Roblox, influencing player engagement significantly.

Read more

Dark Messiah's Thrilling Rooftop Chase by Arkane

Explore the dynamic 2006 game Dark Messiah's rooftop chase, crafted by Arkane, featuring ghouls, parkour, and blacksmithing.

Read more

Microsoft Issues Emergency Updates for MSMQ on Windows

Microsoft released unscheduled updates for MSMQ issues affecting Windows versions. Action required to restore functionality.

Read more

Abiotic Factor 1.2 Update Unveils Holiday Cryosphere

Abiotic Factor introduces Holiday Cryosphere in its 1.2 update, enhancing gameplay with a seasonal twist. Expect expanded features and mysteries.

Read more