Zoho Assist - Tool

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
November 11, 2025
Last Seen
August 6, 2026

Zoho Assist is a legitimate remote support tool that enables remote access to endpoints for troubleshooting.

Overview

Zoho Assist is a legitimate remote support tool that enables remote access to endpoints for troubleshooting. The articles provided do not reference Zoho Assist by name; instead they describe attackers abusing remote-access capabilities via Triofox—via an unauthenticated vulnerability exploited in a UNC6485 campaign and by abusing Triofox's antivirus feature to deploy remote-access tools—underscoring the risk surface of remote-access software and the need for strict access controls and monitoring.

Related Threat Clusters

  • Multiple Attackers Exploit Unpatched SharePoint Servers, Microsoft Reports

    Microsoft's DART team discovered two distinct threat actors operating simultaneously within the same victim network, complicating incident response efforts. The investigation began with ransomware activity linked to…

    5 articles · Updated June 23, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1691 articles · Updated February 12, 2026
  • Exploitation of Triofox CVE-2025-12480 Vulnerability by Hackers

    Hackers are exploiting a critical unauthenticated access vulnerability (CVE-2025-12480) in Gladinet's Triofox file-sharing platform. This flaw allows attackers to bypass authentication and gain administrative access,…

    4 articles · Updated November 11, 2025
  • Exploitation of Triofox Vulnerability CVE-2025-12480 by UNC6485 Threat Group

    Hackers have exploited a critical unauthenticated access vulnerability (CVE-2025-12480) in Gladinet's Triofox file-sharing platform, allowing them to gain unauthorized administrative access and execute remote code. The…

    5 articles · Updated November 12, 2025

Recent Intelligence Reports

  • Google's cybersecurity unit published a blog post — cloud.google.com · August 6, 2026
  • Microsoft Uncovers Parallel Threat Activity From Two Cyberattackers in Single Intrusion — Gbhackers · June 23, 2026
  • Unpatched SharePoint servers opened the door to multiple attackers, Microsoft finds — Csoonline · June 23, 2026
  • Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms — Mandiant · June 5, 2026
  • Employees are unknowingly inviting tech support impersonators into firms, says FBI — Csoonline · May 28, 2026
  • Unauthenticated Remote Access via Triofox Vulnerability Exploited by UNC6485 (Campaign) — Wiz · November 12, 2025
  • Hackers abuse Triofox antivirus feature to deploy remote access tools — Bleepingcomputer · November 11, 2025

CVSS v3.1 Breakdown