GoAnywhere 0-Day RCE Actively Exploited to Deliver Medusa Ransomware
A critical zero-day vulnerability in GoAnywhere MFT's License Servlet is currently being exploited to deploy Medusa ransomware.
A critical zero-day vulnerability in GoAnywhere MFT's License Servlet is currently being exploited to deploy Medusa ransomware.
On Mon, Sep 18, 2025, Fortra released an advisory concerning CVE-2025-10035, a deserialization flaw rated with a CVSS score of 10.0.
Threat actors identified as Storm-1175 have exploited this vulnerability to achieve remote code execution (RCE) on affected systems, leading to widespread compromise.
CVE-2025-10035 affects GoAnywhere MFT versions up to 7.8.3. The flaw allows an attacker to forge a license response signature, bypassing signature verification.
The attacker can send a crafted response, triggering the deserialization of arbitrary objects, resulting in command injection and full RCE.
CVE ID Vulnerability Type Affected Product & Versions CVSS Score (3.1)
CVE-2025-10035 Deserialization flaw GoAnywhere MFT License Servlet Admin Console ≤ 7.8.3 10.0
The vulnerability can be exploited without authentication when valid responses are crafted or intercepted, putting any internet-facing GoAnywhere deployment at significant risk.
A critical zero-day vulnerability in GoAnywhere MFT's License Servlet is currently being exploited to deploy Medusa ransomware.
Successful exploitation allows the attacker to execute system and user discovery commands and install additional tools for lateral movement.
Public guidance strongly recommends immediate updating to the patched GoAnywhere MFT release and reviewing license verification configurations.
Monitoring for unusual requests to the license servlet is also advised to detect exploitation attempts early.
Microsoft Threat Intelligence identified active exploitation beginning Mon, Sep 11, 2025. Storm-1175’s campaign follows a consistent multi-stage pattern:
Initial Access: Exploitation of the zero-day deserialization vulnerability in the License Servlet grants RCE. Persistence: Attackers deploy remote monitoring and management (RMM) tools—SimpleHelp and MeshAgent—within the GoAnywhere process and install web shells via .jsp files in the application directories. Discovery: Threat actors execute commands such as whoami, systeminfo, and net user to map the environment and deploy network scanning tools. Lateral Movement: RDP sessions using mstsc.exe facilitate movement between hosts. Command and Control: RMM tools establish persistent control, often using a Cloudflare tunnel to secure traffic. Exfiltration: Rclone is used to collect and transfer data from compromised networks. Ransomware Deployment: Medusa ransomware encrypts systems, demanding payment for decryption keys.
Organizations should immediately upgrade GoAnywhere MFT to the latest patched version per Fortra’s advisory.
Because patching does not undo prior exploitation, thorough investigation of systems suspected of compromise is essential. Restrict outbound internet access for servers to prevent malicious downloads and command-and-control communications.
Deploy endpoint detection and response (EDR) in block mode to ensure any malicious artifacts are halted, even if they bypass antivirus scans.
Enable automated investigation and remediation to allow rapid response to alerts. Turn on attack surface reduction rules to block common ransomware methods, including preventing web shell creation and restricting executable launches based on trust metrics.
Use an external attack surface management solution to discover unpatched GoAnywhere instances. Continuously monitor license servlet traffic for suspicious signature verification failures.
Finally, leverage Microsoft Defender vulnerability management and XDR capabilities to detect vulnerable devices, alert on exploitation attempts, and coordinate detection and response across the environment.
By combining rapid patching, stringent network controls, and advanced endpoint security, organizations can mitigate the risk posed by this high-severity GoAnywhere MFT vulnerability and disrupt Storm-1175’s Medusa ransomware campaigns.
Based on reporting by GBHackers.
