logo

Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day

ID: a0083258-1010-5161-b79f-941f60a14f68

STIX ID: report--a0083258-1010-5161-b79f-941f60a14f68

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Mayura Kathir

...
...

A coordinated intrusion in June 2026 leveraged a compromised internet-facing Microsoft IIS server and an ASP.NET web shell to conduct rapid hands-on-keyboard activity and automated lateral movement, culminating in deployment of a new Rust-based ransomware family dubbed “Spirals.” Operators escalated privileges, harvested credentials (SAM and LSASS dumps), used WMI and PsExec for mass propagation, disabled endpoint and backup defenses, staged multiple tunneling/C2 tools (revsocks, Chisel, Cloudflare Tunnel) over port 443, and encrypted files using per-file AES-128 with an ECDH P-256 key while threatening data leakage via a Tor negotiation portal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.