A critical zero-day vulnerability in Fortra’s GoAnywhere Managed File Transfer platform came under active exploitation by the threat group tracked as Storm-1175, marking one of the most significant enterprise security incidents of September 2025. Microsoft confirmed that the group, operating as a Medusa ransomware affiliate, leveraged the flaw to breach target networks, establish persistent access, and deploy file-encrypting payloads across compromised environments.
The Threat Landscape
The vulnerability, designated CVE-2025-10035, carries a maximum severity rating and represents a deserialization flaw in the License Servlet of GoAnywhere MFT. The bug allows an attacker with a forged license response signature to deserialize an arbitrary object, potentially leading to remote code execution. Most critically, exploitation requires no user interaction whatsoever — an attacker with network access to the GoAnywhere service can trigger the vulnerability remotely.
WatchTowr Labs first confirmed active exploitation dating back to at least September 10, 2025, a full eight days before Fortra published its public advisory on September 18. Microsoft independently corroborated the timeline, observing Storm-1175 activity matching the group’s established tactics, techniques, and procedures beginning September 11. The gap between initial exploitation and vendor disclosure highlights a persistent challenge in enterprise security: defenders often operate with incomplete threat intelligence while attackers move quickly to exploit newly discovered weaknesses.
For cryptocurrency businesses and exchanges that rely on managed file transfer solutions for secure data movement, this vulnerability presents a particularly acute risk. Attackers who establish footholds in file transfer infrastructure gain access to the data backbone connecting trading systems, compliance workflows, and customer records.
Core Principles
Understanding the GoAnywhere exploit requires grasping the fundamentals of deserialization vulnerabilities. When software receives data from an external source, it must convert that data from a serialized format back into usable objects. If the deserialization process fails to properly validate incoming data, an attacker can craft a malicious payload that executes arbitrary code when the application attempts to reconstruct the object.
In this case, the License Servlet handles license validation responses. By forging a response with a specially crafted signature and embedded malicious object, attackers bypassed the intended license verification flow and injected their own commands into the GoAnywhere process. The maximum severity rating reflects both the ease of exploitation and the complete lack of authentication required — any network-reachable GoAnywhere instance was vulnerable.
The attack chain followed a well-established playbook for ransomware operators: initial access through the zero-day, followed by lateral movement using legitimate remote management tools, data exfiltration, and finally ransomware deployment.
Tooling and Setup
Storm-1175 demonstrated a sophisticated multi-stage approach after gaining initial access. For persistence, the group abused legitimate remote monitoring and management tools including SimpleHelp and MeshAgent, blending their command-and-control traffic with normal IT operations. The actors also deployed Netscan for network reconnaissance, mapping the compromised environment to identify high-value targets.
Lateral movement was accomplished through Microsoft Terminal Services client (mstsc.exe), allowing attackers to pivot between systems using stolen credentials. For data exfiltration, the group deployed Rclone, an open-source file synchronization tool that can stream data to cloud storage providers — effectively turning a legitimate utility into a data theft weapon. The attackers even established a Cloudflare tunnel for secure and encrypted command-and-control communications, making their traffic difficult to distinguish from normal HTTPS connections.
The final stage saw the deployment of Medusa ransomware across the compromised environment, encrypting files and demanding payment for decryption keys. Microsoft confirmed that at least one victim environment experienced complete ransomware deployment.
Ongoing Vigilance
Microsoft’s advisory recommends a comprehensive set of defensive measures. Organizations should update GoAnywhere MFT immediately per Fortra’s guidance, using tools like Defender External Attack Surface Management to locate unpatched instances. Servers should be restricted from making arbitrary outbound internet connections, limiting the effectiveness of tools like Rclone and Cloudflare tunnels.
Additional recommendations include enabling Endpoint Detection and Response in block mode, activating full automated investigation and remediation capabilities, turning on antivirus block mode for cloud-based protection, and applying attack surface reduction rules to block suspicious executable launches, ransomware activity patterns, and web shell creation.
Final Takeaway
The GoAnywhere MFT zero-day exploitation by Storm-1175 serves as a stark reminder that enterprise infrastructure components — not just endpoints or web applications — are prime targets for sophisticated threat actors. Managed file transfer platforms sit at the intersection of internal networks and external data flows, making them ideal pivot points for ransomware operators. With Bitcoin trading above $115,000 and the broader crypto market capitalization exceeding $3.6 trillion, cryptocurrency businesses face an elevated threat landscape where a single unpatched vulnerability can cascade into a catastrophic breach. The eight-day gap between first exploitation and vendor disclosure underscores why organizations cannot rely solely on vendor patches — proactive monitoring, network segmentation, and defense-in-depth strategies are essential.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always consult with qualified security professionals regarding your specific infrastructure needs.
Bug bounties are the most cost-effective security investment
The industry needs standardized security audit frameworks
The amount of DeFi exploits is still way too high
8 days between initial exploitation and vendor disclosure. defenders operating blind for over a week while attackers had full access. this gap is the real vulnerability
Kasper Nielsen the 8 day gap is the industry standard unfortunately. solarwinds was 9 months. 8 days is actually fast compared to most zero day disclosure timelines
watchtowr confirmed exploitation 8 days before fortas advisory. thats a week of free access for storm-1175 to plant ransomware payloads across every unpatched mft instance
Kasper Nielsen 8 days blind is actually better than industry average. most zero-days go months before disclosure. the real question is how many orgs even applied the patch within 48 hours
8 days between exploitation and vendor disclosure. defenders operating blind the whole time. thats the real vulnerability
zero_day_watch 8 days of blind exploitation is the real headline. fortar sat on this for over a week while enterprises were getting encrypted by medusa ransomware
CVE-2025-10035 is a deserialization bug in the license servlet. no auth needed, just network access. this is the exact scenario that keeps secops people up at night
infra_sec_guy no auth needed and just network access. every MFT facing the internet was a sitting duck for a week. how is this even possible in 2025 enterprise software
watchtowr confirmed exploitation 8 days before fortas advisory. storm-1175 had a full week of unrestricted access to enterprise networks. the medusa ransomware deployment was probably just the final stage
Daniela P. 8 days of unrestricted access before disclosure means storm-1175 had time to set up persistence, exfiltrate data, and stage the ransomware payload. the breach wasnt 8 days, the deployment was
medusa ransomware getting enterprise level access through a file transfer tool is peak 2025 cybersecurity. the weakest link is always some third party vendor nobody audited
Bridge security is still the weakest link in the ecosystem
CVE-2025-10035 is max severity and requires zero user interaction. remote code execution on a file transfer platform is basically a skeleton key to enterprise networks
MFT platforms sit at the intersection of internal networks and external partners. one CVSS 10 RCE there and the attacker owns the data backbone of every connected org
mft platforms sit between internal networks and external partners. one cve 10 rce there and attacker owns data backbone
cve-2025-10035 requires zero user interaction. remote code execution on file transfer platform is basically skeleton key to enterprise networks
8 days between exploitation and disclosure is unacceptable for enterprise software
The CVSS 10 score means this is essentially a master key for enterprise networks
File transfer platforms should never have deserialization vulnerabilities
CVE-2025-10035 is a deserialization bug in the license servlet. no auth, no user interaction, just network access. basically a free shell on any exposed GoAnywhere instance
patch_window license servlet deserialization with no auth. basically handed attackers a root shell on a plate. CVSS 10 doesnt even capture how bad this is
156k firewalls exposed and the PoC was public within a week. the gap between disclosure and mass exploitation is effectively zero now. if you ran GoAnywhere and didnt patch within 48 hours you got hit, simple as that