Drooid Logo
Back to story perspectives

Full Breakdown

Microsoft Links Storm-1175 to Exploitation of GoAnywhere MFT Vulnerability

10/8/2025, 12:01:35 AM

Overview of the Vulnerability and Exploitation

Microsoft has identified a critical security vulnerability in Fortra's GoAnywhere Managed File Transfer (MFT) software, tracked as CVE-2025-10035, which has been actively exploited by the cybercriminal group Storm-1175. This deserialization flaw, with a maximum CVSS score of 10.0, allows attackers to execute arbitrary code remotely without authentication, posing significant risks to internet-exposed instances of GoAnywhere MFT. The vulnerability was disclosed by Fortra on September 18, 2025, but exploitation activities were detected as early as September 10, 2025.

Attack Methodology

The exploitation process initiated by Storm-1175 involves several stages:

1. Initial Access: Attackers exploit the deserialization vulnerability to gain remote code execution (RCE).

2. Persistence: They deploy remote monitoring and management (RMM) tools, such as SimpleHelp and MeshAgent, within the GoAnywhere process to maintain access.

3. Discovery: The attackers execute commands for user and system reconnaissance, using tools like Netscan for network mapping.

4. Lateral Movement: Utilizing Windows Remote Desktop Connection (mstsc.exe), they navigate across compromised systems.

5. Command and Control (C2): A Cloudflare tunnel is established for secure communication.

6. Exfiltration and Ransomware Deployment: Data is exfiltrated using Rclone, followed by the deployment of Medusa ransomware, which encrypts systems and demands ransom for decryption.

Implications and Impact

The exploitation of CVE-2025-10035 has raised alarms due to its potential for widespread compromise. Microsoft has reported that over 500 GoAnywhere MFT instances remain exposed online, heightening the urgency for organizations to apply patches and review their security postures. The incident echoes previous ransomware attacks, such as the MOVEit transfer incident, highlighting the vulnerabilities of file transfer platforms.

Official Statements & Responses

Microsoft has urged organizations to immediately upgrade to the patched versions of GoAnywhere MFT (7.8.4 or Sustain Release 7.6.3) and to monitor for signs of compromise. Fortra has faced criticism for its lack of transparency regarding the active exploitation of the vulnerability. Benjamin Harris, CEO of watchTowr, emphasized the need for clarity, stating, “Customers deserve transparency, not silence. We hope they will share in the very near future so affected or potentially affected organizations can understand their exposure.”

Criticism & Opposition

Critics have pointed out that Fortra's delayed communication regarding the vulnerability's exploitation has left many organizations vulnerable. Harris noted that organizations using GoAnywhere MFT have been under "silent assault" since at least September 11, with little guidance from Fortra on how to address the threat. The lack of timely updates has raised concerns about the security practices of software vendors in managing vulnerabilities.

What's Next

Organizations are advised to conduct thorough forensic reviews of their systems to identify any signs of prior compromise. Continuous monitoring of license servlet traffic for unusual activity is also recommended. Microsoft and Fortra are expected to provide further guidance as the situation develops, particularly regarding the ongoing risks associated with the exploitation of CVE-2025-10035.

Verbatim Quotes

  • “confirmed what we feared. Organizations running GoAnywhere MFT have effectively been under silent assault since at least September 11, with little clarity from Fortra.” — Benjamin Harris, CEO of watchTowr
  • “What's still missing are the answers only Fortra can provide. How did threat actors get the private keys needed to exploit this? Why were organizations left in the dark for so long? Customers deserve transparency, not silence. We hope they will share in the very near future so affected or potentially affected organizations can understand their exposure to a vulnerability that is being actively exploited in the wild.” — Benjamin Harris, CEO of watchTowr
  • “Customers deserve transparency, not silence.” — Benjamin Harris, CEO of watchTowr

This situation underscores the critical importance of timely patching and proactive security measures to mitigate the risks posed by emerging vulnerabilities in widely used software.