logo

Medusa Ransomware Actors Exploit Critical Fortra GoAnywhere Flaw

ID: 6f00c9dc-98ab-584d-928f-f8e085edffba

STIX ID: report--6f00c9dc-98ab-584d-928f-f8e085edffba

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-10-07

Date Updated: 2026-05-05

Author: Rob Wright

...
...

Microsoft observed Storm-1175 exploiting a critical deserialization flaw (CVE-2025-10035) in Fortra's GoAnywhere MFT as a zero-day, resulting in at least one confirmed Medusa ransomware deployment; the campaign was observed on Sept. 11, before the vendor patch. Analysts question how attackers satisfied a required private-key license signature—raising possibilities of a leaked/stolen key or compromised Fortra infrastructure. Fortra released patches and advisories, Microsoft published IoCs and mitigation guidance, and CISA added the flaw to its Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.