Vulnerability Patched in Triofox Platform Exploited by Hackers

11 Nov 2025

Mandiant Threat Defense has revealed exploitation of a critical vulnerability in Gladinet's Triofox platform, tracked as CVE-2025-12480.

Timeline and Actions

The flaw, with a CVSS score of 9.1, allowed unauthorized access to Triofox's configuration pages. Attackers used this access to upload and execute arbitrary data by creating a native admin account named Cluster Admin. Mandiant observed these activities by threat cluster UNC6485 starting from 2025-08-24.

  • Triofox users were vulnerable starting 2025-08-24.
  • Exploit allowed attackers to execute malicious files as SYSTEM.
  • Exploitation included deploying Zoho Assist and AnyDesk for deeper intrusion.
  • Actions recommended: update Triofox, audit admin accounts.

Exploitation Details

Attackers configured the antivirus scanner to a malicious script named "centre_report.bat." This script downloaded Zoho UEMS installer files from 84.200.80.252 to support remote access via tools like Zoho Assist, enabling reconnaissance and privilege escalation efforts. Additional tools such as Plink and PuTTY were employed to establish SSH tunnels over port 443, facilitating inbound Remote Desktop Protocol (RDP) access.

Mandiant advises clients to update Triofox to the latest version, carefully audit administrator accounts, and ensure the antivirus settings prohibit unauthorized script execution.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6448607
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1298366
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
498815
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454623
downloads

News and reviews for Desktop Windows

Crafting a Plague Mask in Kingdom Come: Deliverance 2

Players can craft a plague mask in Kingdom Come: Deliverance 2 by collecting essential items near Sedletz Monastery.

Read more

Anno 117 Earns Top Rating on Metacritic

Anno 117 outperforms its predecessors in Metacritic scores for 2025 strategy games.

Read more

Windows 11 May Introduce Advanced Haptics for Mice and Trackpads

Microsoft's new 'haptic signals' in Windows 11 could enhance feedback for peripherals, offering a tactile buzz for various actions.

Read more

Arc Raiders Sells Over 4 Million Copies, Sets Player Record

Arc Raiders hits 4 million sales, breaks Steam player record. Nexon's biggest global launch.

Read more

Bethesda Adds Creations Bundle to Fallout 4 Amid Criticism

Bethesda's Creations Bundle for Fallout 4 faces issues: player reports of crashes and missing content.

Read more

Bungie Embraces 'Extraction Shooter' Label Despite Criticism

Bungie sticks with 'Extraction shooter' term for Marathon, despite criticism from former director Chris Sides over its clarity in distinguishing games.

Read more

Steam's Animal Fest 2025 Offers Unique PC Game Deals Until 2023-11-17

Animal Fest 2025 on Steam offers significant discounts on animal-themed PC games, running until 2023-11-17.

Read more

Arcane Trigger Offers Free Steam Demo with Unique Bullet System

Arcane Trigger, a retro wizard shooter by MiniWhale and Anotherindie, releases a free demo on Steam, featuring a unique bullet-building system.

Read more

PC Gamer's Top 2025 Reviews: Games That Made the Cut

PC Gamer reveals top games of 2025, highlighting scoring criteria and surprises in reviews.

Read more

Vulnerability Patched in Triofox Platform Exploited by Hackers

Mandiant reveals n-day attacks on Triofox. Patch now for enhanced security.

Read more