
Microsoft attributes G oAnywhere attacks to storm-1175
Microsoft has confirmed that a cybercriminal group known as Storm-1175 is actively exploiting a critical vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) software to deploy the Medusa ransomware. The disclosure sheds new light on a wave of attacks that have been quietly unfolding since early September, targeting organizations running unpatched versions of the file transfer platform.
The exploited flaw, tracked as CVE-2025-10035 , is a critical deserialization vulnerability t hat carries a perfect CVSS score of 10.0. It allows attackers to execute arbitrary code remotely and without authentication. Microsoft’s Threat Intelligence team said the issue stems from the way GoAnywhere validates license response signatures. By forging a valid-looking signature, attackers can trick the software into deserializing malicious data, leading to command injection and potential remote code execution (RCE).
Microsoft attributed the ongoing campaign to Storm-1175 , a financially motivated threat actor notorious for deploying the Medusa ransomware. The group has a history of targeting public-facing applications to gain initial access to corporate networks. Microsoft says Storm-1175 has been exploiting the GoAnywhere flaw since September 11, 2025.
The security research firm watchTowr first detected signs of exploitation as early as September 10, indicating attackers may have had a head start of several weeks before public awareness grew.
How the Attack Works :
Once Storm-1175 successfully exploits the vulnerability, the group deploys remote monitoring and management (RMM) tools such as SimpleHelp and MeshAgent to establish persistence and maintain control of compromised systems. Investigators have also observed the creation of .jsp webshell files inside GoAnywhere directories at the same time as these RMM tools, providing secondary access points.
After gaining a foothold, the attackers perform user, system, and network discovery, using built-in Windows tools to map the environment. They then leverage mstsc.exe, Microsoft’s Remote Desktop Connection utility, for lateral movement across the network.
For command-and-control (C2), the attackers use Cloudflare tunnels to disguise outbound traffic, while Rclone has been observed in at least one victim environment to exfiltrate stolen data. The attack sequence typically culminates in the deployment of Medusa ransomware , encrypting systems and disrupting operations.
Why It Matters :
The CVE-2025-10035 flaw represents one of the most severe vulnerabilities in recent months, not only due to its critical CVSS score but also because it allows unauthenticated remote code execution. GoAnywhere MFT is widely used by enterprises to securely transfer sensitive data, making it a prime target for ransomware operators.
Security experts warn that the combination of silent exploitation, persistence mechanisms, and data theft amplifies the potential damage. Organizations that have not yet patched their GoAnywhere instances may already be compromised.
Benjamin Harris, CEO and founder of watchTowr, criticized Fortra’s response to the incident, saying the company failed to communicate the severity of the issue in time. “Organizations running GoAnywhere MFT have effectively been under silent assault since at least September 11, with little clarity from Fortra,” Harris said. “What’s still missing are the answers only Fortra can provide. How did threat actors get the private keys needed to exploit this? Why were organizations left in the dark for so long?”
Harris urged Fortra to provide greater transparency about the root cause and timeline of the breach, emphasizing that customers “deserve answers, not silence.”
Evidence indicates that the campaign began around September 10–11, 2025 , with global victims across industries using GoAnywhere MFT. While Microsoft has not publicly named affected organizations, indicators of compromise have been observed in enterprise and government networks worldwide.
The discovery underscores the growing trend of ransomware actors exploiting supply-chain and infrastructure software vulnerabilities to gain a foothold in enterprise networks. As Microsoft’s findings reveal, what began as a quiet flaw in a file transfer tool has now become another front in the ongoing battle against ransomware.
