logo

New Spirals Ransomware Encrypts Victim Network in Under 24 Hours

ID: d44c837d-c082-54ce-a858-431675e98f14

STIX ID: report--d44c837d-c082-54ce-a858-431675e98f14

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

...
...

**Executive Summary:** The report describes a new, fast-acting ransomware group called _Spirals_ that completes initial access, credential harvesting, lateral movement, data exfiltration, and network-wide encryption in under 24 hours using a double-extortion model; indicators include a .spirals file extension and READ_ME_SPIRALS.txt ransom notes, and the advisory contains detection and mitigation recommendations (patching, MFA, offline backups, monitoring for LSASS/Kerberoast activity).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.