Hackers abuse Triofox antivirus feature to deploy remote access tools
ID: e04a0119-08e5-58ca-a1a5-759c25026e58
STIX ID: report--e04a0119-08e5-58ca-a1a5-759c25026e58
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** Security researchers (GTIG/Mandiant) observed UNC6485 exploiting CVE-2025-12480 in Gladinet Triofox to bypass authentication via spoofed Host/Referer headers, gain admin access, and abuse the product's antivirus executable path to run SYSTEM-level code, deploy remote-access tools (Zoho Assist, AnyDesk), and perform lateral movement; patches and IoCs have been published and administrators are urged to update and audit configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
