Unauthenticated Remote Access via Triofox Vulnerability Exploited by UNC6485 (Campaign)
ID: 18445d20-99ba-5f96-b665-e711da9e3e88
STIX ID: report--18445d20-99ba-5f96-b665-e711da9e3e88
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-11-12
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Mandiant researchers observed UNC6485 actively exploiting CVE-2025-12480 in Gladinet Triofox (affecting versions before 16.7.10368.56560) by spoofing the Host/localhost header to bypass authentication, create an admin account, and abuse the anti-virus configuration to run SYSTEM-level scripts. The attackers deployed a disguised Zoho UEMS installer from 84.200.80.252 to install Zoho Assist and AnyDesk for persistent remote access, used renamed utilities (silcon.exe, sihosts.exe) to establish an SSH reverse tunnel over port 433 for inbound RDP, and performed reconnaissance, privilege escalation, and lateral movement; Mandiant confirmed a fix is available and recommended immediate upgrading.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
