logo

Spirals ransomware locks down victim systems in under 24 hours

ID: 55569f27-a0f8-5e79-9308-93952152e567

STIX ID: report--55569f27-a0f8-5e79-9308-93952152e567

Feed Name: Help Net Security

Threat Score
78/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Sinisa Markovic

...
...

Symantec Threat Hunter Team observed a fast-moving ransomware attack by a previously unknown Rust-based strain called "Spirals" against an IT services company in South Asia; attackers gained access via a compromised IIS server and ASP.NET web shell, escalated privileges (UAC bypass), dumped credentials (SAM/LSASS), established persistent and tunneled access (reverse SOCKS, renamed Chisel, Cloudflare Tunnel), disabled security/backup services, and encrypted files using per-file AES-128 keys wrapped with an ECDH P-256 key, leaving a Tor-based ransom negotiation site and threatening data leaks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.