Skip to content

Hackers Exploiting Triofox 0

Cybersecuritynews November 11, 2025

Google Mandiant has disclosed active exploitation of CVE-2025-12480, a critical unauthenticated access vulnerability in Gladinet’s Triofox file-sharing platform.

The threat cluster tracked as UNC6485 has been weaponizing this flaw since August 2025 to gain unauthorized administrative access and establish persistent remote control over compromised systems.

The vulnerability stems from improper access control validation in Triofox versions 16.4.10317.56372 and earlier.

Attackers exploit an HTTP host header injection technique, modifying the Host header to “localhost” to bypass authentication checks and access the sensitive AdminDatabase.aspx configuration page.

This page typically displays only during initial setup. However, it becomes exposed when the authentication function CanRunCriticalPage() fails to validate the request origin properly.

Once authenticated, attackers create new administrative accounts and escalate privileges within the application.

The exploitation chain becomes particularly dangerous when combined with Triofox’s built-in anti-virus feature misconfiguration.

Attackers can set arbitrary executable paths for the anti-virus scanner, which then runs under the SYSTEM account the highest privilege level in Windows environments.

In documented attacks, threat actors uploaded malicious batch scripts to published file shares, then configured them as the anti-virus engine path.

When files are uploaded to the , the malicious script executes automatically with SYSTEM privileges, enabling complete system compromise. Post-exploitation activities reveal the severity of these breaches.

Attackers deployed Zoho Unified Endpoint Management agents, followed by AnyDesk. They renamed the Plink utilities to establish encrypted SSH reverse tunnels to command-and-control servers.

This infrastructure enabled attackers to forward RDP traffic over encrypted channels, maintaining persistent remote desktop access while evading network-based detection systems.

Mandiant successfully contained the affected environment within 16 minutes of alert detection, leveraging Google Security Operations’ composite detection capabilities.

Identifying anomalous remote access tool deployment and suspicious file staging activities.

Gladinet released a patched version 16.7.10368.56560 addressing the vulnerability.

Mandiant recommends immediate upgrades across all affected deployments and comprehensive audits of administrative accounts.

Verification that anti-virus engines execute only authorized binaries, and monitoring for anomalous outbound SSH tunnel traffic indicating potential compromise or lateral movement attempts within enterprise networks.

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Ivanti has rolled out security updates for its Endpoint Manager product, addressing three high-severity vulnerabilities…

A sophisticated remote data-wipe attack targeting Android devices has emerged, exploiting Google's Find Hub service…

Synology has released an urgent security update addressing a critical remote code execution vulnerability in…

A surge in attacks exploiting iCalendar (.ics) files as a sophisticated threat vector that bypasses…

A sophisticated supply chain attack has emerged, targeting industrial control systems through compromised .NET packages.…

A security vulnerability has been discovered in Zoom Workplace VDI Client for Windows that could…