Medusa ransomware used during exploitation of GoAnywhere file transfer bug, Microsoft says
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10035 | Deserialization Flaw in Fortra GoAnywhere MFT License Servlet Enables RCE CVE-2025-10035 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in the License Servlet of Fortra GoAnywhere Managed File Transfer (MFT). It is triggered when the servlet processes a license response carrying a validly forged signature, causing it to deserialize an arbitrary attacker-controlled object; the CVSS vector indicates the attack is network-based and requires no privileges or user interaction. Successful exploitation can lead to command injection (CWE-77), effectively giving an attacker command execution on the MFT server and access to the files and credentials that flow through it. Any organization running GoAnywhere MFT, which is commonly deployed as a central file-transfer hub, is affected, although specific affected/fixed version ranges are not provided in the available data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2025-09-29 with known ransomware use, Microsoft attributes attacks to the Storm-1175 ransomware affiliate (Medusa, now reportedly replaced by StormEncryptor), and EPSS assigns a 99.8% probability of exploitation within 30 days. Do: Apply mitigations or patches per Fortra's vendor instructions immediately, as this is a KEV entry carrying BOD 22-01 requirements for federal agencies (patch or discontinue use if mitigations are unavailable). Because a ransomware affiliate (Storm-1175, using Medusa/StormEncryptor) is actively exploiting it, hunt for compromise: review License Servlet traffic and logs for forged license responses, check for unexpected processes or new accounts, and look for signs of lateral movement. Until patched, restrict or remove internet exposure of GoAnywhere MFT admin and license interfaces. | 9.8 | 100% | KEV ransomware |
| moderatelow thousands of internet-exposed GoAnywhere MFT instances (estimate) |
Full article526 words · extracted from therecord.media · click to collapse
Cybercriminals are using the Medusa ransomware strain during exploitation of a vulnerability in a popular file transfer tool recently highlighted by federal cybersecurity officials. Microsoft published a report on Monday analyzing exploitation activity in multiple organizations involving CVE-2025-10035 — a critical vulnerability in Fortra's GoAnywhere managed file transfer solution. The researchers attributed the activity to a cybercriminal group they call Storm-1175, noting that the threat actors are known for deploying the Medusa ransomware and for exploiting public-facing applications for initial access. “The impact of CVE-2025-10035 is amplified by the fact that, upon successful exploitation, attackers could perform system and user discovery, maintain long-term access, and deploy additional tools for lateral movement and malware,” the company said. After using the vulnerability for initial access, the hackers used the remote monitoring and management tools SimpleHelp and MeshAgent before moving laterally across systems within the compromised network. The researchers said they saw the successful deployment of Medusa ransomware in one compromised environment. Fortra initially warned the public about the bug on September 18, saying they discovered it the week before, but the company has continually declined to say if they are aware of it being exploited by cybercriminals. According to Microsoft, exploitation was observed on September 11, the same day Fortra said they discovered the bug. Last week, the Cybersecurity and Infrastructure Security Agency (CISA) also confirmed that the vulnerability has been exploited and ordered all federal civilian agencies to patch the bug by October 20. For weeks prior to CISA’s notice, cybersecurity experts at the security firm watchTowr warned GoAnywhere users that the vulnerability was being exploited. Company CEO Benjamin Harris told Recorded Future News that organizations running the file transfer tool “have effectively been under silent assault since at least September 11, with little clarity from Fortra.” Fortra did not respond to requests for comment. “Microsoft’s confirmation now paints a pretty unpleasant picture — exploitation, attribution, and a month-long head start for the attackers,” Harris said. “What’s still missing are the answers only Fortra can provide. How did threat actors get the private keys needed to exploit this? Why were organizations left in the dark for so long?” The Medusa ransomware has been used to attack more than 300 organizations in critical infrastructure sectors since emerging in 2021, according to CISA and the FBI. Medusa drew widespread attention in 2023 for an attack on Minneapolis Public Schools that exposed troves of sensitive student documents impacting more than 100,000 people. In addition to attacks on the Pacific island nation of Tonga, it has targeted municipalities in France and government agencies in the Philippines as well as a technology company created by two of Canada’s largest banks. Government bodies in Illinois and Texas have also been affected by the group’s attacks. The group most recently took credit for an attack on NASCAR.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/medusa-ransomware-exploited-file-transfer