Plink - Tool

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
November 11, 2025
Last Seen
August 7, 2026

The provided articles do not describe a cybersecurity tool or attacker named 'Plink.' Instead, they focus on Triofox vulnerabilities being exploited by UNC6485 to gain unauthenticated remote access and to deploy remote-access tools via Triofox’s antivirus features.

Overview

The provided articles do not describe a cybersecurity tool or attacker named 'Plink.' Instead, they focus on Triofox vulnerabilities being exploited by UNC6485 to gain unauthenticated remote access and to deploy remote-access tools via Triofox’s antivirus features. This highlights how remote-access software with built-in features can be abused for persistence and tool deployment, underscoring risk from such applications in cybersecurity.

Related Threat Clusters

Recent Intelligence Reports

  • T1036 — attack.mitre.org · August 7, 2026
  • APT34 (OilRig): Espionage on Your Infrastructure — Kelacyber · July 22, 2026
  • Putty — www.chiark.greenend.org.uk · June 10, 2026
  • Unauthenticated Remote Access via Triofox Vulnerability Exploited by UNC6485 (Campaign) — Wiz · November 12, 2025
  • Hackers abuse Triofox antivirus feature to deploy remote access tools — Bleepingcomputer · November 11, 2025
  • Hackers Exploiting Triofox 0 — Cybersecuritynews · November 11, 2025

CVSS v3.1 Breakdown