Vulnerability Patched in Triofox Platform Exploited by Hackers

11 Nov 2025

Mandiant Threat Defense has revealed exploitation of a critical vulnerability in Gladinet's Triofox platform, tracked as CVE-2025-12480.

Timeline and Actions

The flaw, with a CVSS score of 9.1, allowed unauthorized access to Triofox's configuration pages. Attackers used this access to upload and execute arbitrary data by creating a native admin account named Cluster Admin. Mandiant observed these activities by threat cluster UNC6485 starting from 2025-08-24.

  • Triofox users were vulnerable starting 2025-08-24.
  • Exploit allowed attackers to execute malicious files as SYSTEM.
  • Exploitation included deploying Zoho Assist and AnyDesk for deeper intrusion.
  • Actions recommended: update Triofox, audit admin accounts.

Exploitation Details

Attackers configured the antivirus scanner to a malicious script named "centre_report.bat." This script downloaded Zoho UEMS installer files from 84.200.80.252 to support remote access via tools like Zoho Assist, enabling reconnaissance and privilege escalation efforts. Additional tools such as Plink and PuTTY were employed to establish SSH tunnels over port 443, facilitating inbound Remote Desktop Protocol (RDP) access.

Mandiant advises clients to update Triofox to the latest version, carefully audit administrator accounts, and ensure the antivirus settings prohibit unauthorized script execution.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7304732
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1682275
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
721238
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
489579
downloads

News and reviews for Desktop Windows

Hytale Enters Early Access with Promising Potential

Hytale, launched into early access after its revival, shows promise despite its unfinished features.

Read more

Hytale Launches: Tops Twitch with 420K Viewers

Hytale debuts in early access, becoming Twitch's most-watched game with 420,000 viewers, signaling significant interest.

Read more

Hytale Launches with Over 344K Twitch Viewers

Hytale, the Minecraft rival, launched to 344K Twitch viewers, marking a key moment for Hypixel Studios and gamers worldwide.

Read more

CheatHappens Offers Discounted Lifetime Subscription for Gaming Trainers

CheatHappens now offers a lifetime subscription for $49.99, granting access to 27,000 trainers and CoSMOS tools for PC games.

Read more

Ubisoft Labels Assassin's Creed Games 'Quadruple-A'

Ubisoft calls Assassin's Creed Mirage and Shadows 'quadruple-A'; raises debate on meaning and impact.

Read more

Amistech Releases My Winter Car in Early Access with Increased Challenge

My Winter Car, a successor to My Summer Car, launched by Amistech on 2023-12-29, promises heightened difficulty and unique survival mechanics.

Read more

Secure Microsoft Bundle for PCs at $39.97

Get the Microsoft bundle with Office 2021 and Windows 11 Pro for $39.97. Enhance old PCs with new tools and OS for 2026 productivity.

Read more

Blue Prince Available on Steam with 34% Discount

Blue Prince is now on sale on Steam during Detective Fest until 2024-01-19, offering players a 34% discount.

Read more

Critical Patch Addressed in Apex Central by Trend Micro

Trend Micro fixed a severe vulnerability in Apex Central, preventing remote code execution. Patch is critical for system security.

Read more

Reignbreaker Available for Under $1 in Limited Bundle Offer

Reignbreaker, a punk roguelike, offers dynamic combat similar to Hades. Available now under $1 via the Killer Bundle.

Read more