Threat Advisory

Exploitation of GoAnywhere MFT Vulnerability Leading to Ransomware Deployment

Threat: Vulnerability/Ransomware
Threat Actor Name: Storm-1175
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A newly disclosed and actively exploited severe flaw (CVE-2025-10035) in the GoAnywhere Managed File Transfer (MFT) system has triggered widespread concern within the cybersecurity community. This critical deserialization issue in the License Servlet Admin Console affects versions up to 7.8.3 and allows attackers to bypass signature verification by forging license response signatures. Through this process, they can inject malicious objects and execute arbitrary code remotely. The vulnerability has been actively exploited by a threat actor known as Storm-1175, which has previously been linked to the Medusa ransomware operation. The exposure of file transfer infrastructure, often containing sensitive or regulated data, makes this flaw particularly high impact. The situation underscores the importance of quickly addressing vulnerabilities in third-party enterprise applications, which continue to serve as high-value entry points for advanced cybercriminal groups.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A newly disclosed and actively exploited severe flaw (CVE-2025-10035) in the GoAnywhere Managed File Transfer (MFT) system has triggered widespread concern within the cybersecurity community. This critical deserialization issue in the License Servlet Admin Console affects versions up to 7.8.3 and allows attackers to bypass signature verification by forging license response signatures. Through this process, they can inject malicious objects and execute arbitrary code remotely. The vulnerability has been actively exploited by a threat actor known as Storm-1175, which has previously been linked to the Medusa ransomware operation. The exposure of file transfer infrastructure, often containing sensitive or regulated data, makes this flaw particularly high impact. The situation underscores the importance of quickly addressing vulnerabilities in third-party enterprise applications, which continue to serve as high-value entry points for advanced cybercriminal groups.[emaillocker id="1283"]

 

The flaw, identified as CVE-2025-10035, arises from insecure deserialization within the License Servlet component of GoAnywhere MFT. Improper validation of license response signatures enables an attacker to craft a forged payload that the application will deserialize and execute, resulting in full remote code execution. The exploitation chain observed in the wild involves Storm-1175 using this entry vector to infiltrate corporate networks. Once inside, the attackers deploy Remote Monitoring and Management (RMM) tools such as SimpleHelp and MeshAgent to maintain persistence and evade detection. They also implant JSP web shells within GoAnywhere directories to ensure ongoing access and perform internal reconnaissance using tools like netscan and mstsc. Following network mapping and privilege escalation, the actors establish command-and-control channels via RMM utilities and Cloudflare tunnels, exfiltrate sensitive data using Rclone, and eventually deploy the Medusa ransomware payload. This sequence reflects a methodical and multi-stage intrusion combining exploitation, persistence, data theft, and system encryption.

 

CVE-2025-10035 represents a critical security concern due to its ease of exploitation and confirmed use in active ransomware operations. The threat actor activity linked to this vulnerability demonstrates how rapidly adversaries weaponize newly disclosed software flaws to infiltrate and monetize enterprise networks. Immediate action is required to mitigate risk: organizations should upgrade to the latest GoAnywhere MFT version, isolate potentially exposed instances, and conduct full compromise assessments to identify unauthorized changes or web shells. Restricting administrative console access from the public internet and enforcing strong authentication controls are also essential. Continuous network monitoring should be prioritized to detect suspicious activity related to RMM tools, tunneling utilities, or data exfiltration behavior. Advanced endpoint protection, automated remediation, and attack surface visibility solutions can further strengthen defenses. Addressing this issue promptly will help prevent disruption and financial impact stemming from ransomware deployment and data extortion campaigns tied to this vulnerability.

THREAT PROFILE:

Tactic Technique ID Technique Sub‑Technique
Initial access T1190 Exploit Public‑Facing Application —
Persistence T1505.003 Server Software Component Web Shell
Discovery T1046 Network Service Discovery —
Command and control T1102 Web Service —
Exfiltration T1567.002 Exfiltration Over Web Service Exfiltration to Cloud Storage
Impact T1486 Data Encrypted for Impact —

RECOMMENDATION:

  • We strongly recommend you update Fortra GoAnywhere MFT to version 7.8.4 or Sustain Release 7.6.3.

 

REFERENCES:

The following reports contain further technical details:

 

[/emaillocker]
crossmenu