GoAnywhere MFT exploitation after CVE-2025-10035
Case score 73
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 73
- Main story score
- 66
- Related evidence lift
- +7 / 20
- Contributing updates
- 3
- Context updates
- 1
- Vulnerability Lead vulnerability anchor: CVE-2025-10035 in GoAnywhere MFT. main
- Exploitation Wave Confirms active exploitation, public exposure conditions, and ransomware use tied to the same flaw. contributes
- Campaign Adds Microsoft’s Storm-1175 attribution and the broader Medusa intrusion pattern. contributes
- Security Patch Release Patch and mitigation guidance for CVE-2025-10035; retained as remediation context. context
Overview
Latest development Open development history Microsoft discloses Storm-1175's high-tempo Medusa ransomware campaign Microsoft disclosed that Storm-1175 has been weaponizing n-day and zero-day exploits in high-tempo Medusa ransomware attacks for the past three years, exploiting at least 16 vulnerabilities since 2023 and including CVE-2025-10035 in GoAnywhere Managed File Transfer. Microsoft said the activity has recently affected healthcare, education, professional services, and finance organizations in Australia, the UK, and the US, with the group typically racing between vulnerability disclosure and patch adoption.
-
Fortra identifies CVE-2025-10035 in GoAnywhere MFT
During a security check on September 11, 2025, Fortra identified that GoAnywhere customers with an Admin Console accessible over the internet could face unauthorized third-party exposure from a deserialization flaw in the License Servlet, where a validly forged license response signature could let an actor deserialize an arbitrary actor-controlled object and possibly reach command injection.
-
Storm-1175 high-velocity Medusa ransomware campaign
Microsoft says Storm-1175, a China-based financially motivated cybercriminal group linked to Medusa ransomware, is rapidly weaponizing n-day and zero-day flaws, sometimes within 24 hours and sometimes before patches are released. The operators chain multiple exploits with new user account creation, remote monitoring and management software deployment, credential theft, and security software disabling to move from initial access to data exfiltration and Medusa ransomware deployment. Recent activity has affected healthcare, education, professional services, and finance organizations in Australia, the United Kingdom, and the United States, with exploited products including GoAnywhere MFT, SmarterMail, Microsoft Exchange, Papercut, Ivanti Connect Secure and Policy Secure, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, and BeyondTrust.
-
Storm-1175 exploits CVE-2025-10035 in GoAnywhere for Medusa ransomware
Microsoft attributed Storm-1175 to exploiting CVE-2025-10035 in Fortra GoAnywhere MFT to gain initial access and deploy Medusa ransomware against affected GoAnywhere environments. The critical deserialization flaw can permit unauthenticated command injection and potential RCE, and Microsoft said activity has been observed since September 10-11, 2025. The post-exploitation chain includes dropping SimpleHelp and MeshAgent, creating .jsp files in GoAnywhere MFT directories, using mstsc.exe for lateral movement, running Rclone for exfiltration, and using a Cloudflare tunnel for C2.
-
Fortra releases GoAnywhere MFT patches for CVE-2025-10035
On September 19, 2025, Fortra released GoAnywhere MFT 7.8.4 and Sustain Release 7.6.3 to patch CVE-2025-10035 and advised administrators to remove public access from the GoAnywhere Admin Console if they cannot upgrade immediately, because exploitation is highly dependent on systems being externally exposed to the internet.