Unc6485 — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 12, 2025
Last Seen
November 14, 2025

Related Threat Clusters

  • Exploitation of Triofox CVE-2025-12480 Vulnerability by Hackers

    Hackers are exploiting a critical unauthenticated access vulnerability (CVE-2025-12480) in Gladinet's Triofox file-sharing platform. This flaw allows attackers to bypass authentication and gain administrative access,…

    4 articles · Updated November 11, 2025
  • Exploitation of Triofox Vulnerability CVE-2025-12480 by UNC6485 Threat Group

    Hackers have exploited a critical unauthenticated access vulnerability (CVE-2025-12480) in Gladinet's Triofox file-sharing platform, allowing them to gain unauthorized administrative access and execute remote code. The…

    5 articles · Updated November 12, 2025
  • Cybercrime Networks Targeting U.S. and Global Entities

    Recent cybersecurity incidents involve various actors targeting U.S. policy experts, exploiting vulnerabilities, and engaging in crypto fraud. Notable activities include Iranian hackers using cyber reconnaissance for…

    3 articles · Updated November 21, 2025
  • Cybercrime Networks Disrupted Amid Ongoing Exploits and Attacks

    Authorities have dismantled major cybercrime networks, including SIM-box fraudsters and ransomware operations. Recent exploits include UNC6485 targeting Triofox for remote code execution and SleepyDuck leveraging…

    5 articles · Updated November 21, 2025

Recent Intelligence Reports

  • The Good, the Bad and the Ugly in Cybersecurity — Sentinelone · November 14, 2025
  • Unauthenticated Remote Access via Triofox Vulnerability Exploited by UNC6485 (Campaign) — Wiz · November 12, 2025

CVSS v3.1 Breakdown