logo

New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

ID: 755e66de-c834-5680-898e-a9bb52f5131c

STIX ID: report--755e66de-c834-5680-898e-a9bb52f5131c

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Kavichselvan

...
...

A previously unseen Rust-based ransomware family called “Spirals” compromised an internet-facing IIS server at an IT services company in June 2026 and achieved full network encryption in under 24 hours. Attackers used an ASP.NET web shell, layered tunneling (Chisel disguised as chrome.exe and a Cloudflare tunnel), privilege escalation and LSASS memory dumps, then automated lateral movement via WMI and mass deployment with PsExec; they disabled Defender and critical backup/database/virtualization services, staged a disguised encryptor (bitsadmin.exe) in SYSVOL, and left a ransom note directing victims to a Tor negotiation portal. Symantec provided IOCs including 185.141.216.194 and recommended web-shell detection, behavioral auditing for WMI/PsExec activity, and credential protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.