Vulnerability Patched in Triofox Platform Exploited by Hackers

11 Nov 2025

Mandiant Threat Defense has revealed exploitation of a critical vulnerability in Gladinet's Triofox platform, tracked as CVE-2025-12480.

Timeline and Actions

The flaw, with a CVSS score of 9.1, allowed unauthorized access to Triofox's configuration pages. Attackers used this access to upload and execute arbitrary data by creating a native admin account named Cluster Admin. Mandiant observed these activities by threat cluster UNC6485 starting from 2025-08-24.

  • Triofox users were vulnerable starting 2025-08-24.
  • Exploit allowed attackers to execute malicious files as SYSTEM.
  • Exploitation included deploying Zoho Assist and AnyDesk for deeper intrusion.
  • Actions recommended: update Triofox, audit admin accounts.

Exploitation Details

Attackers configured the antivirus scanner to a malicious script named "centre_report.bat." This script downloaded Zoho UEMS installer files from 84.200.80.252 to support remote access via tools like Zoho Assist, enabling reconnaissance and privilege escalation efforts. Additional tools such as Plink and PuTTY were employed to establish SSH tunnels over port 443, facilitating inbound Remote Desktop Protocol (RDP) access.

Mandiant advises clients to update Triofox to the latest version, carefully audit administrator accounts, and ensure the antivirus settings prohibit unauthorized script execution.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6439969
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1295266
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
498154
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454492
downloads

News and reviews for Desktop Windows

PC Gamer's Top 2025 Reviews: Games That Made the Cut

PC Gamer reveals top games of 2025, highlighting scoring criteria and surprises in reviews.

Read more

Vulnerability Patched in Triofox Platform Exploited by Hackers

Mandiant reveals n-day attacks on Triofox. Patch now for enhanced security.

Read more

Bazzite: An Alternative to Windows for Gamers

Bazzite offers a gaming-centric OS alternative to Windows 10, appealing to Steam users but with limitations in creative apps and game services.

Read more

Tailside: Cozy Cafe Sim Releases on Steam 2026-01-21

Tailside launches on Steam January 21, 2026. Players manage a cozy café featuring fluffy creatures.

Read more

Resident Evil 4 Remake Hits Lowest Price at $16.79

Resident Evil 4 remake is on sale for $16.79 until 2025-11-16. Enhancements include updated visuals and gameplay. Secure this deal now.

Read more

Discover Hidden Windows 11 Apps Enhancing Productivity

Explore free, overlooked Windows 11 apps boosting productivity in 2025 without ads or upsells.

Read more

Will Glow the Wisp Free on Steam Until 2023-11-11

Will Glow the Wisp, inspired by Xbox classics, is free on Steam briefly, delighting indie game fans.

Read more

Expand PlayStation Games Library on PC with Top Titles

Top PlayStation games now on PC are expanding gaming options with remasters and exclusives.

Read more

Windows XP Revival: Nostalgic Apps Run on Virtual Machine

Windows XP returns via a virtual machine in 2025 to replay 3D Pinball, Movie Maker, and TweakUI.

Read more

Adds Water Simulation in Enshrouded's Wake of the Water Update

Enshrouded's new update introduces dynamic water environments. Explore Veilwater Basin and new combat options now. Available on Steam for $29.99.

Read more