Vulnerability Patched in Triofox Platform Exploited by Hackers

11 Nov 2025

Mandiant Threat Defense has revealed exploitation of a critical vulnerability in Gladinet's Triofox platform, tracked as CVE-2025-12480.

Timeline and Actions

The flaw, with a CVSS score of 9.1, allowed unauthorized access to Triofox's configuration pages. Attackers used this access to upload and execute arbitrary data by creating a native admin account named Cluster Admin. Mandiant observed these activities by threat cluster UNC6485 starting from 2025-08-24.

  • Triofox users were vulnerable starting 2025-08-24.
  • Exploit allowed attackers to execute malicious files as SYSTEM.
  • Exploitation included deploying Zoho Assist and AnyDesk for deeper intrusion.
  • Actions recommended: update Triofox, audit admin accounts.

Exploitation Details

Attackers configured the antivirus scanner to a malicious script named "centre_report.bat." This script downloaded Zoho UEMS installer files from 84.200.80.252 to support remote access via tools like Zoho Assist, enabling reconnaissance and privilege escalation efforts. Additional tools such as Plink and PuTTY were employed to establish SSH tunnels over port 443, facilitating inbound Remote Desktop Protocol (RDP) access.

Mandiant advises clients to update Triofox to the latest version, carefully audit administrator accounts, and ensure the antivirus settings prohibit unauthorized script execution.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6676074
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1400175
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
556678
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
461183
downloads

News and reviews for Desktop Windows

Helldivers 2 Offers 31% Black Friday Discount for 24 Hours

Helldivers 2 gets a significant 31% discount for Black Friday, available for one day, providing a cost-effective gaming experience.

Read more

Valve Defends AI Disclosures on Steam Amid Criticism

Valve advocates for AI disclosures in gaming, arguing they inform consumers. Critics question their necessity.

Read more

Clair Obscur Discount: Save 45% on PC Purchase

Clair Obscur: Expedition 33, a turn-based RPG by Sandfall Interactive, is 45% off on PC. Offer available during Black Friday 2025.

Read more

New Mod Manager for Total War: Warhammer 3 Launched

Creative Assembly introduces Total War: Warhammer 3 mod manager in early access on Steam, aiming for improved mod management.

Read more

Fanatical Offers Arc Raiders Key in GOTY Bundle

Fanatical now offers Arc Raiders Steam keys for $1 in its Mystery Gem packs, expanding players' game libraries.

Read more

Icarus' Long-Awaited Expansion Introduces Elysium Region

Dangerous Horizons expansion for Icarus adds Elysium region and more. Created by RocketWerkz, it enhances gameplay with new features and narratives.

Read more

Captain Wayne: New Shooter Launches with Unique Features

Captain Wayne, launched in the Doom engine, offers a campaign and horde mode for $10. Sale ends 2023-12-09.

Read more

Last Epoch Adds Paid DLC, Sparks Review Concerns

Eleventh Hour Games plans to add paid Paradox Classes to Last Epoch in 2026, causing a decline in Steam reviews to 'Mixed'.

Read more

Rainbow Six Siege Adds Steam Achievements After 10 Years

Ubisoft enhances Rainbow Six with retroactive Steam Achievements, benefiting completionists.

Read more

Stranger Things Returns to Dead by Daylight in January 2026

Dead by Daylight welcomes Stranger Things back this January with new characters and a map, delighting fans worldwide.

Read more