Executive Summary
In September 2024, Microsoft Threat Intelligence announced that Storm-1175, a financially motivated ransomware affiliate, exploited a critical zero-day vulnerability (CVE-2025-10035) in Fortra's GoAnywhere MFT file transfer solution. Attackers gained remote code execution, established persistence via remote monitoring tools and web shells, performed lateral movement using legitimate Windows utilities, and exfiltrated data with Rclone before deploying Medusa ransomware in targeted organizations. Impacted sectors included transportation, education, retail, insurance, and manufacturing. The initial compromises began on September 11, days before the vulnerability was publicly disclosed or patched, giving attackers a significant advantage and facilitating stealthy, high-impact breaches due to delayed vendor transparency.
This incident highlights the escalating sophistication of ransomware operations leveraging zero-day exploits and legitimate IT tools to evade detection, resulting in substantial business disruption and data loss. Growing regulatory scrutiny and industry concern underscore the urgent need for rapid threat intelligence sharing, proactive zero trust measures, and improved vendor communication in light of similar recent attacks.
Why This Matters Now
This breach demonstrates the urgent risks posed by undisclosed software vulnerabilities and delayed vendor responses, empowering attackers with a valuable head start. The incident underscores the necessity of rapid patch management, zero trust enforcement, and transparent threat reporting as ransomware groups increasingly target file transfer software through novel attack paths.
Attack Path Analysis
Storm-1175 exploited a zero-day vulnerability (CVE-2025-10035) in GoAnywhere MFT to gain initial access to target environments. Upon compromise, attackers deployed web shells and remote monitoring tools to escalate privileges and establish persistence. Using Windows utilities and remote management tools, they moved laterally within network segments to access additional systems. They maintained command and control via covert remote access utilities. Data was exfiltrated using tools like Rclone before ultimately deploying Medusa ransomware to encrypt data and disrupt operations. Each stage leveraged stealth and legitimate tooling to maximize impact and evade detection.
Kill Chain Progression
Initial Compromise
Description
Exploitation of the GoAnywhere MFT zero-day (CVE-2025-10035) enabled remote code execution on publicly exposed file transfer infrastructure.
Related CVEs
CVE-2025-10035
CVSS 9.8A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Affected Products:
Fortra GoAnywhere MFT – All versions prior to 2025-09-18
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter
Server Software Component: Web Shell
Valid Accounts
System Services: Service Execution
Remote Services: SMB/Windows Admin Shares
Exfiltration Over C2 Channel
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Security of Public-Facing Web Applications
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9
CISA Zero Trust Maturity Model 2.0 – Secure Application Development, Vulnerability Management
Control ID: Pillar: Applications
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Transportation
Storm-1175 ransomware attacks explicitly targeted transportation sector via GoAnywhere MFT exploitation, threatening critical file transfers and operational continuity systems.
Higher Education/Acadamia
Education sector faces severe ransomware exposure through GoAnywhere vulnerabilities, risking student data theft and administrative system disruption via lateral movement.
Retail Industry
Retail organizations vulnerable to Medusa ransomware deployment through file transfer compromises, threatening payment processing systems and customer data protection compliance.
Insurance
Insurance sector at high risk from Storm-1175 attacks targeting sensitive client data through compromised file transfer services and network segmentation failures.
Sources
- Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate Storm-1175https://cyberscoop.com/microsoft-goanywhere-ransomware-storm-1175/Verified
- CISA Adds Five Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2025/09/29/cisa-adds-five-known-exploited-vulnerabilities-catalogVerified
- NVD - CVE-2025-10035https://nvd.nist.gov/vuln/detail/CVE-2025-10035Verified
- Fortra Security Advisory FI-2025-012https://www.fortra.com/security/advisories/product-security/fi-2025-012Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust Segmentation, East-West Traffic Security, Threat Detection, and Egress Policy Enforcement provided by CNSF could have detected or contained attacker movement, data theft, and ransomware deployment—limiting cross-network propagation and preventing unauthorized exfiltration.
Control: Cloud Firewall (ACF)
Mitigation: Ingress traffic from untrusted sources could be blocked or tightly restricted.
Control: Threat Detection & Anomaly Response
Mitigation: Rapid anomaly detection of unauthorized tool deployment and behavioral deviations.
Control: East-West Traffic Security
Mitigation: Lateral movement attempts between sensitive assets would be constrained and monitored.
Control: Inline IPS (Suricata)
Mitigation: Suspicious command and control traffic can be detected and blocked in real time.
Control: Egress Security & Policy Enforcement
Mitigation: Egress filtering prevents unauthorized data transfers to attacker-controlled endpoints.
Segmentation contains ransomware spread and limits blast radius.
Impact at a Glance
Affected Business Functions
- File Transfer Operations
- Data Exchange Processes
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive data transferred via GoAnywhere MFT, including customer information and proprietary business data.
Recommended Actions
Key Takeaways & Next Steps
- • Harden the cloud perimeter by restricting direct access to public-facing applications and patch rapidly.
- • Implement Zero Trust Segmentation and East-West Traffic Security to contain lateral movement across network zones.
- • Enforce robust egress policies to monitor and restrict sensitive data transfers and third-party tool communications.
- • Deploy Threat Detection and automated anomaly response capabilities to detect early signs of compromise and suspicious behavior.
- • Continuously monitor workload behavior and enforce least privilege network access policies to limit ransomware impact.



