Executive Summary
In early 2025, Medusa ransomware operators—tracked as Storm-1175—successfully exploited a critical vulnerability (CVE-2025-10035) in the Fortra GoAnywhere Managed File Transfer (MFT) platform. The attack required access to a private key, indicating either an advanced intrusion or insider compromise. Once inside, the threat actors moved laterally to deploy ransomware payloads, seizing sensitive business data and disrupting managed file transfers for impacted organizations. Multiple enterprises suffered data theft, business downtime, and reputational damage as a result.
This incident underscores an ongoing trend of targeting supply chain platforms and MFT products with ransomware via sophisticated access methods. As ransomware groups become more resourceful in exploiting zero-days and leveraging stolen keys, organizations must prioritize proactive threat detection, timely patching, and tighter access controls to counter these evolving tactics.
Why This Matters Now
This exploitation highlights the growing urgency to secure MFT and supply chain solutions against advanced ransomware actors who are actively developing and leveraging zero-day vulnerabilities. The Medusa attack demonstrates that privileged credentials and keys remain highly sought-after entry points, demanding immediate defensive focus and improved key management strategies.
Attack Path Analysis
Attackers obtained the necessary private key to exploit CVE-2025-10035 in Fortra GoAnywhere, resulting in initial unauthorized access. They escalated privileges within the compromised environment, likely leveraging available credentials or vulnerabilities. Lateral movement ensued as the attackers traversed internal networks and workloads to broaden access. Command and Control channels were established to maintain communication and control, helping orchestrate further actions. Sensitive data was then exfiltrated from the environment via egress channels. Finally, the attackers deployed ransomware to encrypt data, causing business disruption and demanding ransom payment.
Kill Chain Progression
Initial Compromise
Description
Exploitation of the Fortra GoAnywhere CVE-2025-10035 using a stolen or otherwise acquired private key gave attackers a foothold in the environment.
Related CVEs
CVE-2025-10035
CVSS 10A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an attacker with a validly forged license response signature to deserialize an arbitrary actor-controlled object, potentially leading to command injection and remote code execution.
Affected Products:
Fortra GoAnywhere MFT – <= 7.8.3
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Network Sniffing
Phishing
Data Encrypted for Impact
Data from Cloud Storage Object
Remote Services
Windows Management Instrumentation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Access Control Measures
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy & Access Privileges
Control ID: 500.03, 500.07
DORA (Digital Operational Resilience Act) – ICT Risk Management & Incident Handling
Control ID: Art. 10, Art. 11
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: Identity Pillar
NIS2 Directive – Security of Network and Information Systems
Control ID: Art. 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Medusa ransomware exploiting Fortra GoAnywhere creates critical risk for financial institutions using file transfer systems, requiring enhanced egress security and threat detection capabilities.
Health Care / Life Sciences
Healthcare organizations face severe HIPAA compliance violations from CVE-2025-10035 exploitation, demanding encrypted traffic protection and zero trust segmentation for patient data security.
Government Administration
Government agencies vulnerable to Storm-1175 threat actors leveraging private key exploitation for lateral movement, necessitating multicloud visibility and anomaly detection systems.
Information Technology/IT
IT sector directly impacted by Fortra GoAnywhere vulnerabilities requiring immediate Kubernetes security implementation and inline IPS deployment to prevent ransomware propagation.
Sources
- Medusa Ransomware Actors Exploit Critical Fortra GoAnywhere Flawhttps://www.darkreading.com/vulnerabilities-threats/medusa-ransomware-exploit-fortra-goanywhere-flawVerified
- Deserialization Vulnerability in GoAnywhere MFT's License Servlethttps://www.fortra.com/security/advisories/product-security/fi-2025-012Verified
- CVE-2025-10035 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-10035Verified
- Investigating active exploitation of CVE-2025-10035 GoAnywhere Managed File Transfer vulnerabilityhttps://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, egress policy enforcement, east-west traffic controls, and inline threat detection would have limited attacker movement, surfaced anomalous behaviors, and blocked data theft and ransomware activity within the cloud environment.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline enforcement and real-time inspection would rapidly detect and alert on exploit signatures or anomalous access.
Control: Zero Trust Segmentation
Mitigation: Identity-based segmentation limits attacker movement and privilege expansion paths.
Control: East-West Traffic Security
Mitigation: Lateral movement is blocked or detected between workloads and services.
Control: Egress Security & Policy Enforcement
Mitigation: Egress filtering and policy enforcement block unauthorized outbound channels and malware C2 connections.
Control: Egress Security & Policy Enforcement
Mitigation: Exfiltration attempts are detected and blocked via egress controls and observability.
Anomalous encryption and ransomware behaviors are rapidly surfaced and contained.
Impact at a Glance
Affected Business Functions
- File Transfer Operations
- Data Management
Estimated downtime: 5 days
Estimated loss: $5,000,000
Potential exposure of sensitive files and credentials due to unauthorized access and data exfiltration.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit the blast radius of initial compromise and restrict lateral movement.
- • Enforce robust east-west traffic controls and monitor for unauthorized workload-to-workload communications.
- • Apply comprehensive egress filtering and outbound policy enforcement to detect and block data exfiltration and C2 communications.
- • Deploy inline threat detection and real-time anomaly response across cloud workloads and applications.
- • Maintain centralized multicloud visibility and control to swiftly identify and remediate cloud-based threats.



