Executive Summary
In September 2025, a cybercrime group tracked as Storm-1175 exploited a critical zero-day deserialization vulnerability (CVE-2025-10035) in Fortra's GoAnywhere Managed File Transfer (MFT) solution. The attackers gained initial access by remotely targeting vulnerable MFT instances and leveraged remote monitoring tools (SimpleHelp, MeshAgent) for persistence. Subsequently, they conducted network reconnaissance with Netscan, moved laterally using Microsoft RDP, exfiltrated sensitive data with Rclone, and ultimately deployed Medusa ransomware payloads to encrypt files. This campaign affected multiple organizations, exposing unpatched systems to significant operational risk and data loss.
The incident highlights a continued surge in ransomware operations leveraging zero-day vulnerabilities in widely used enterprise software. Attackers are increasingly exploiting supply chain and infrastructure components to maximize impact, driving regulatory scrutiny and accelerating the need for robust patch management and segmentation practices.
Why This Matters Now
This incident demonstrates the urgency of patching critical vulnerabilities in third-party enterprise file transfer tools, as threat actors are weaponizing zero-day flaws for rapid compromise and extortion. The exploitation of GoAnywhere MFT by Medusa ransomware underscores the growing risks posed by sophisticated affiliates targeting supply chain technologies, making proactive security and detection essential.
Attack Path Analysis
Storm-1175 exploited a zero-day deserialization vulnerability (CVE-2025-10035) in publicly exposed GoAnywhere MFT instances for initial access. The attackers established persistence using remote monitoring and management (RMM) tools, then performed network reconnaissance and lateral movement with tools such as Netscan and RDP. Command and control was achieved via RMM beacons and interactive access. They exfiltrated sensitive files using Rclone and finally deployed Medusa ransomware to encrypt victim data and disrupt operations.
Kill Chain Progression
Initial Compromise
Description
Attacker exploited CVE-2025-10035 (GoAnywhere MFT deserialization flaw) on exposed internet-facing servers to gain initial access.
Related CVEs
CVE-2025-10035
CVSS 10A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Affected Products:
Fortra GoAnywhere MFT – < 7.8.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Create Account
Remote Access Software
Remote System Discovery
Remote Services: Remote Desktop Protocol
Exfiltration Over C2 Channel
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Security of Public-Facing Applications
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Article 15(1)
CISA Zero Trust Maturity Model (ZTMM 2.0) – Continuous Monitoring and Vulnerability Management
Control ID: Asset Management - Devices
NIS2 Directive – Basic Cybersecurity Risk-management Measures
Control ID: Article 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Critical exposure through GoAnywhere MFT file transfers enables ransomware infiltration, compromising sensitive financial data and regulatory compliance requirements including PCI DSS standards.
Health Care / Life Sciences
Medusa ransomware exploitation of GoAnywhere vulnerabilities threatens patient data confidentiality, HIPAA compliance, and critical healthcare operations requiring secure file transfers.
Government Administration
Over 300 critical infrastructure organizations impacted by Storm-1175 attacks exploiting GoAnywhere MFT, creating national security risks and compromising citizen data protection.
Information Technology/IT
IT sectors face direct vulnerability through GoAnywhere MFT deployments, enabling lateral movement, data exfiltration via Rclone, and comprehensive network compromise scenarios.
Sources
- Microsoft: Critical GoAnywhere bug exploited in ransomware attackshttps://www.bleepingcomputer.com/news/security/microsoft-critical-goanywhere-bug-exploited-in-ransomware-attacks/Verified
- Deserialization Vulnerability in GoAnywhere MFT's License Servlethttps://www.fortra.com/security/advisories/product-security/fi-2025-012Verified
- CVE-2025-10035 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-10035Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust network segmentation, lateral movement controls, egress policy enforcement, and inline threat detection would have sharply limited adversary movement, data theft, and the spread of ransomware in this attack. CNSF-aligned capabilities provide layered safeguards to confine attackers, detect malicious activity, and prevent data exfiltration or encryption at critical kill chain stages.
Control: Cloud Firewall (ACF)
Mitigation: Reduces exposed attack surface by limiting direct internet access to MFT services.
Control: Zero Trust Segmentation
Mitigation: Restricts lateral escalation opportunities by limiting accessible resources based on identity and least privilege.
Control: East-West Traffic Security
Mitigation: Contains and detects unauthorized intra-network traffic indicative of lateral movement.
Control: Threat Detection & Anomaly Response
Mitigation: Alerts on abnormal remote access usage or command & control channel establishment.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks and logs attempts to exfiltrate sensitive data over unauthorized egress paths.
Detects and blocks known ransomware payloads or malicious encryption behaviors in real-time.
Impact at a Glance
Affected Business Functions
- File Transfer Operations
- Data Exchange Services
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive data due to unauthorized access and command execution.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce strict network segmentation and zero trust access policies around all public-facing applications, especially file transfer and management systems.
- • Regularly validate egress controls to prevent unauthorized outbound communications and data exfiltration from critical workloads.
- • Deploy inline intrusion prevention and threat detection to promptly identify RMM tool misuse, ransomware payloads, and lateral movement behaviors.
- • Implement central visibility and continuous monitoring across multi-cloud/hybrid infrastructure to rapidly detect changes and anomalous activities.
- • Promptly patch internet-exposed endpoints and routinely audit for misconfigurations to reduce exploitable attack surfaces.



