Exploitation of GoAnywhere MFT Vulnerability by Storm-1175: Impact, Tactics, and Lessons Learned
A single vulnerability in a widely used file transfer tool—GoAnywhere MFT—has become the launchpad for a wave of cyberattacks orchestrated by the group Storm-1175. This flaw, tracked as CVE-2025-10035, has enabled attackers to breach over 500 exposed systems, unleashing Medusa ransomware and siphoning sensitive data from organizations across multiple sectors. The Shadowserver Foundation’s monitoring underscores just how many organizations left their doors open, often unknowingly, to this threat. What makes this incident especially alarming is the attackers’ use of legitimate remote monitoring and management (RMM) tools—like SimpleHelp and MeshAgent—to maintain their foothold, blending seamlessly into normal IT operations. The exploitation of GoAnywhere MFT isn’t just a technical mishap; it’s a stark illustration of how quickly cybercriminals can pivot from zero-day discovery to widespread compromise, leaving a trail of encrypted files and stolen data in their wake (BleepingComputer, 2025).
Impact and Implications of the GoAnywhere MFT Vulnerability Exploitation
Widespread Exploitation and Affected Entities
The exploitation of the GoAnywhere MFT vulnerability by the cybercrime group Storm-1175 has had significant repercussions across various sectors. The vulnerability, identified as CVE-2025-10035, has been actively exploited in Medusa ransomware attacks. Over 500 instances of GoAnywhere MFT have been exposed online, as monitored by the Shadowserver Foundation, although the exact number of unpatched systems remains unclear. This widespread vulnerability has been leveraged by Storm-1175 to target multiple organizations, leading to data breaches and ransomware deployments.
Technical Exploitation Tactics
Storm-1175 has utilized a sophisticated set of tactics to exploit the GoAnywhere MFT vulnerability. The group has been exploiting a deserialization of untrusted data weakness in the License Servlet of Fortra’s GoAnywhere MFT tool. This vulnerability allows for remote exploitation without requiring user interaction, making it a low-complexity attack vector. Once initial access is gained, the attackers maintain persistence by abusing remote monitoring and management (RMM) tools such as SimpleHelp and MeshAgent. These tools facilitate the execution of further malicious activities within the compromised network.
Ransomware Deployment and Data Exfiltration
Following the initial exploitation, Storm-1175 has been observed deploying ransomware payloads, specifically Medusa, to encrypt victims’ files. The group has also engaged in data exfiltration activities, utilizing tools like Rclone to transfer stolen files from the compromised systems. The deployment of ransomware and the exfiltration of sensitive data have severe implications for the affected organizations, leading to operational disruptions and potential financial losses.
Broader Cybersecurity Implications
The exploitation of the GoAnywhere MFT vulnerability highlights broader cybersecurity challenges faced by organizations. The ability of cybercriminals to exploit zero-day vulnerabilities underscores the importance of timely patch management and vulnerability assessments. Additionally, the use of RMM tools by attackers to maintain persistence within networks raises concerns about the security of these tools and the need for robust monitoring and access controls.
Recommendations for Mitigation and Prevention
To mitigate the impact of the GoAnywhere MFT vulnerability exploitation, organizations are advised to take several proactive measures. Firstly, it is crucial to upgrade to the latest versions of the GoAnywhere MFT tool, as recommended by Microsoft and Fortra. Additionally, organizations should conduct thorough inspections of their log files for stack trace errors with the SignedObject.getObject string to identify potential compromises. Implementing strong access controls, regular vulnerability assessments, and employee training on cybersecurity best practices can further enhance an organization’s resilience against such attacks.
In conclusion, the exploitation of the GoAnywhere MFT vulnerability by Storm-1175 serves as a stark reminder of the evolving threat landscape and the need for continuous vigilance and proactive cybersecurity measures.
Final Thoughts
The GoAnywhere MFT vulnerability saga is a wake-up call for organizations relying on third-party tools for critical operations. Storm-1175’s exploitation campaign demonstrates how attackers can weaponize even a single overlooked flaw, leveraging both custom malware and legitimate IT tools to maximize impact. As ransomware and data exfiltration tactics evolve, so too must our defenses—timely patching, vigilant monitoring, and robust access controls are no longer optional. The incident also highlights the growing risks posed by remote management software, which, while essential for IT teams, can become a double-edged sword in the wrong hands. Staying ahead of threats like those posed by Storm-1175 requires not just technical fixes, but a culture of continuous vigilance and proactive security practices (BleepingComputer, 2025).
References
- Cimpanu, C. (2025, March 12). Microsoft: Critical GoAnywhere bug exploited in ransomware attacks. BleepingComputer. https://www.bleepingcomputer.com/news/security/microsoft-critical-goanywhere-bug-exploited-in-ransomware-attacks/