Validated Containment Architectures are here. →Explore

Executive Summary

In September 2025, a cybercrime group tracked as Storm-1175 exploited a critical zero-day deserialization vulnerability (CVE-2025-10035) in Fortra's GoAnywhere Managed File Transfer (MFT) solution. The attackers gained initial access by remotely targeting vulnerable MFT instances and leveraged remote monitoring tools (SimpleHelp, MeshAgent) for persistence. Subsequently, they conducted network reconnaissance with Netscan, moved laterally using Microsoft RDP, exfiltrated sensitive data with Rclone, and ultimately deployed Medusa ransomware payloads to encrypt files. This campaign affected multiple organizations, exposing unpatched systems to significant operational risk and data loss.

The incident highlights a continued surge in ransomware operations leveraging zero-day vulnerabilities in widely used enterprise software. Attackers are increasingly exploiting supply chain and infrastructure components to maximize impact, driving regulatory scrutiny and accelerating the need for robust patch management and segmentation practices.

Why This Matters Now

This incident demonstrates the urgency of patching critical vulnerabilities in third-party enterprise file transfer tools, as threat actors are weaponizing zero-day flaws for rapid compromise and extortion. The exploitation of GoAnywhere MFT by Medusa ransomware underscores the growing risks posed by sophisticated affiliates targeting supply chain technologies, making proactive security and detection essential.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach revealed weaknesses in patch management, east-west traffic security, and egress controls, putting organizations at risk of data exfiltration and regulatory violations.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust network segmentation, lateral movement controls, egress policy enforcement, and inline threat detection would have sharply limited adversary movement, data theft, and the spread of ransomware in this attack. CNSF-aligned capabilities provide layered safeguards to confine attackers, detect malicious activity, and prevent data exfiltration or encryption at critical kill chain stages.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Reduces exposed attack surface by limiting direct internet access to MFT services.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Restricts lateral escalation opportunities by limiting accessible resources based on identity and least privilege.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Contains and detects unauthorized intra-network traffic indicative of lateral movement.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Alerts on abnormal remote access usage or command & control channel establishment.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Blocks and logs attempts to exfiltrate sensitive data over unauthorized egress paths.

Impact (Mitigations)

Detects and blocks known ransomware payloads or malicious encryption behaviors in real-time.

Impact at a Glance

Affected Business Functions

  • File Transfer Operations
  • Data Exchange Services
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive data due to unauthorized access and command execution.

Recommended Actions

  • Enforce strict network segmentation and zero trust access policies around all public-facing applications, especially file transfer and management systems.
  • Regularly validate egress controls to prevent unauthorized outbound communications and data exfiltration from critical workloads.
  • Deploy inline intrusion prevention and threat detection to promptly identify RMM tool misuse, ransomware payloads, and lateral movement behaviors.
  • Implement central visibility and continuous monitoring across multi-cloud/hybrid infrastructure to rapidly detect changes and anomalous activities.
  • Promptly patch internet-exposed endpoints and routinely audit for misconfigurations to reduce exploitable attack surfaces.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image