UNC6485
UNC6485 is a threat cluster tracked by Google Threat Intelligence Group (GTIG)/Mandiant that has been observed exploiting the Gladinet Triofox vulnerability CVE-2025-12480 as early as August 24, 2025. The activity involved an HTTP Host header attack, setting the Host header to "localhost" to bypass authentication and access Triofox configuration and setup pages. UNC6485 used this access to rerun the initial setup process and create a new native administrative account named "Cluster Admin," then abused Triofox’s built-in anti-virus feature to execute attacker-controlled scripts with SYSTEM privileges. Observed post-exploitation activity included uploading and executing a batch script, downloading a disguised Zoho UEMS installer from 84.200.80[.]252, and deploying Zoho Assist and AnyDesk for persistent remote access. Mandiant also observed use of renamed PuTTY and Plink utilities (including silcon.exe and sihosts.exe) to establish SSH reverse tunnels, including tunneling RDP externally over port 433. Additional reported follow-on actions included reconnaissance, enumeration of SMB sessions and user accounts, attempted password changes, and attempts to add accounts to local administrators and Domain Admins groups. Mandiant detected related staging activity such as file downloads to C:\WINDOWS\Temp. The cluster is directly associated in the provided content with exploitation of Triofox; no further attribution or nation-state linkage is stated.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UNC6485 exploited a zero-day vulnerability (CVE-2025-12480) in Gladinet Triofox to achieve unauthenticated remote code execution, leveraging a complex attack chain involving authentication bypass, rogue database setup, admin account creation, file upload, and abuse of antivirus configuration for code execution.
UNC6485 is a threat cluster known for exploiting improper access control vulnerabilities in enterprise file-sharing platforms such as Gladinet Triofox.
UNC6485 is actively exploiting CVE-2025-12480, an improper access control vulnerability in Gladinet Triofox, to gain SYSTEM-level access, establish persistence, deploy remote access tools, steal data, and potentially move laterally within customer networks.
UNC6485 is known for exploiting CVE-2025-12480, an improper access control vulnerability in Gladinet Triofox.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.