UNC6485
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:22:42
Targeted industries: professional-services technology-and-telecommunications
Context
UNC6485 is a cyber-espionage group exploiting CVE-2025-12480 in Gladinet’s Triofox file-sharing platform to gain initial network access and establish long-term persistence. They create unauthorized administrative accounts and deploy RATs, utilizing legitimate tools like Zoho Assist and AnyDesk to evade detection. Their TTPs indicate a sophisticated understanding of the platform, allowing them to blend malicious activities with legitimate administrative actions.
Exploited vulnerabilities
- CVE-2025-12480 (vulnerability)
Reports & references
- cloud.google.com — Triofox Vulnerability Cve 2025 12480 (report)