GoAnywhere 0-Day RCE Vulnerability Exploited in the Wild to Deploy Medusa Ransomware
A critical deserialization vulnerability in GoAnywhere MFT's License Servlet, identified as CVE-2025-10035 , has been exploited by the Storm-1175 group for executing Medusa ransomware.
A critical deserialization vulnerability in GoAnywhere MFT's License Servlet, identified as CVE-2025-10035 , has been exploited by the Storm-1175 group for executing Medusa ransomware.
This vulnerability impacts GoAnywhere MFT versions up to 7.8.3, specifically in the License Servlet Admin Console. It allows threat actors to forge a license response signature, bypassing validation checks and enabling command injection into the Java process for remote code execution on exposed systems.
The flaw does not require authentication once a validly signed payload is crafted or intercepted, making exploitation straightforward on unpatched systems.
Successful exploitation allows system and user enumeration, persistence, and deployment of additional tools for lateral movement and data exfiltration.
Immediate patching is crucial. Administrators should upgrade to the versions specified in Fortra’s advisory and audit potentially compromised environments.
Microsoft Threat Intelligence has attributed active exploitation to Storm-1175, known for targeting public-facing applications.
Initial access is gained via the deserialization vulnerability in GoAnywhere MFT. Subsequently, Storm-1175 deploys RMM binaries, such as MeshAgent and SimpleHelp, into the GoAnywhere service directory, and creates JSP web shells for remote access.
Post-exploitation activities include running PowerShell commands to enumerate users, groups, domain trust relationships, and network interfaces. Command and control channels are established through RMM tools , often concealed via Cloudflare.
This vulnerability impacts GoAnywhere MFT versions up to 7.8.3, specifically in the License Servlet Admin Console.
Data exfiltration is conducted using rclone, transferring stolen data to attacker-controlled cloud storage. The final stage involves encrypting victim assets with Medusa ransomware , identified by Microsoft Defender as Ransom Win32/Medusa.
Risk Factors Details
Affected Products GoAnywhere MFT License Servlet Admin Console versions below 7.8.3
Impact Command injection leading to remote code execution
Exploit Prerequisites Validly forged or intercepted license response signature
CVSS 3.1 Score 10.0 (Critical)
Upgrade immediately to the patched GoAnywhere MFT version as per Fortra's instructions.
Configure perimeter firewalls and proxies to block unauthorized outbound connections from GoAnywhere servers.
Enable EDR in Block Mode to allow Microsoft Defender for Endpoint to block malicious artifacts.
Deploy Attack Surface Reduction Rules to prevent common ransomware techniques, such as blocking unauthorized executable files and disabling web shell creation.
Monitor with External Attack Surface Management tools to identify unmanaged or unpatched GoAnywhere instances.
Utilize Automated Investigations and remediation features in Microsoft Defender to reduce response time and alert fatigue.
Adopting a defense-in-depth strategy that includes rapid patching, network segmentation, and advanced endpoint protection can help prevent exploitation attempts and mitigate the impact of Storm-1175 Medusa ransomware.
Based on reporting by Cyber Security News.
