logo

Critical RCE (CVE-2025-10035) in GoAnywhere MFT Used by Medusa Ransomware Group

ID: 9f3d6ce5-5754-5417-b78f-7fef5163f609

STIX ID: report--9f3d6ce5-5754-5417-b78f-7fef5163f609

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

Author: Ddos

...
...

Microsoft observed active exploitation of a critical deserialization vulnerability (CVE-2025-10035, CVSS 10.0) in GoAnywhere MFT by the criminal group Storm-1175; attackers bypassed signature verification to achieve unauthenticated RCE, installed legitimate RMM tools for persistence, used Cloudflare tunnels for C2, exfiltrated data with Rclone, and deployed Medusa ransomware — organizations are urged to apply vendor patches and hunt for post-compromise indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.