VỮNG MÃI MỘT NIỀM TIN

GoAnywhere MFT Hit by Critical Vulnerability: Storm-1175 Exploits to Deploy Medusa Ransomware Summary

  • 08/10/2025


1. A Serious Cyberattack Campaign

A large-scale cyberattack campaign has recently raised serious global cybersecurity concerns. Storm-1175, a threat group long monitored by Microsoft, has exploited the CVE-2025-10035 vulnerability in GoAnywhere MFT to deliver Medusa ransomware.

This vulnerability, rated with the highest severity level (CVSS 10.0), was exploited as a zero-day beginning in early September 2025 — before the official patch was released.


2. What Is GoAnywhere MFT?

GoAnywhere MFT (Managed File Transfer) is a secure file transfer platform widely used by financial institutions, healthcare organizations, and large enterprises to share data internally or with partners.

However, the CVE-2025-10035 flaw resides in the License Servlet component — a web module responsible for handling software licensing information. The issue stems from a “deserialization of untrusted data” vulnerability, where the software processes input data without verifying its integrity or safety.

This allows attackers to execute arbitrary code remotely on the server without requiring any user interaction.


3. Exploitation Timeline and Impact

Fortra released a patch on September 18, 2025, but researchers at WatchTowr Labs discovered that the vulnerability had been exploited nearly a week earlier, making it a true zero-day.

According to Microsoft, Storm-1175 (linked to the Medusa ransomware group) began exploiting GoAnywhere MFT on September 11, 2025, compromising multiple organizations.


4. Detailed Attack Chain

The attack begins when Storm-1175 exploits the vulnerability in the License Servlet component to execute arbitrary code and gain control of the GoAnywhere MFT server. Once inside, the attackers install remote management tools (RMM) such as SimpleHelp and MeshAgent to maintain persistent access and establish long-term control channels.

Next, they scan the internal network using Netscan to gather system and user information, identify privileged accounts, and map out critical assets. Based on this reconnaissance, they perform lateral movement through Remote Desktop (mstsc.exe) to compromise additional servers within the network.

In the final phase, the attackers use Rclone to exfiltrate sensitive data, then deploy Medusa ransomware to encrypt entire systems and extort victims. This attack chain demonstrates a carefully planned and technically coordinated operation, employing multiple tactics and tools commonly used by advanced persistent threat (APT) groups, making detection and response highly challenging.


5. Links to Previous Campaigns

The GoAnywhere MFT exploitation by Storm-1175 is not an isolated incident but part of a broader pattern of ransomware activity observed across multiple high-profile campaigns.

In March 2025, CISA and the FBI warned about a Medusa ransomware campaign that affected more than 300 critical infrastructure organizations in the United States, including those in the healthcare, energy, and education sectors. These attacks shared common characteristics — exploiting vulnerabilities in management or file transfer systems, leveraging legitimate credentials to hide activity, and maintaining persistence within the network.

Previously, in 2024, Microsoft also documented Storm-1175’s involvement in exploiting VMware ESXi servers to spread Akira and Black Basta ransomware — two sophisticated strains known for their rapid encryption capabilities and focus on large corporate environments.

The recurring presence of Storm-1175 in major ransomware incidents suggests that the group operates with high technical proficiency, structured organization, and a strategy of reusing tools, infrastructure, and attack techniques (TTPs) across campaigns. This highlights the importance of sharing Indicators of Compromise (IoCs) and applying timely security patches across industries to prevent similar threats.


6. Current Situation

According to the Shadowserver Foundation, more than 500 GoAnywhere MFT servers remain exposed to the Internet, with an unknown number still unpatched.

Given that MFT platforms often handle sensitive files and customer data, successful exploitation could lead to data breaches, full system encryption, service disruption, and severe financial loss for affected organizations.


7. Recommendations for Administrators

  • Update GoAnywhere MFT immediately to the latest patched version.

  • Review system logs, especially entries containing "SignedObject.getObject", as potential signs of exploitation.

  • Restrict network access, allowing only trusted internal IPs or hosts.

  • Monitor for unauthorized installations of RMM tools or data transfer utilities like Rclone.

  • Perform regular data backups and store copies on isolated systems to mitigate ransomware damage.


🔒 Security Lessons

The CVE-2025-10035 vulnerability clearly demonstrates that even “secure” platforms can become critical attack vectors if not regularly updated and monitored.

As Medusa ransomware continues expanding its targets, patch management, proactive monitoring, and security auditing are no longer optional — they are essential steps to avoid catastrophic “lockout” scenarios that could cripple entire networks.

Sometimes, it takes just one overlooked vulnerability in a “secure” system to open the door wide for attackers.


Partner