New Spirals ransomware encrypts victim network in under 24 hours
ID: 3704e52c-c97b-58dd-ada8-08adc6343c77
STIX ID: report--3704e52c-c97b-58dd-ada8-08adc6343c77
Feed Name: Bleeping Computer
Symantec researchers observed a rapid corporate intrusion by a newly identified ransomware actor called Spirals that compromised a public IIS server, uploaded an ASP.NET web shell, bypassed UAC, enabled RDP, created persistent accounts, dumped credentials, moved laterally via WMI to dozens of hosts, disabled Defender and backup/database services, and deployed a Rust-based ransomware (named bitsadmin.exe) to encrypt files and threaten data exposure — all within 24 hours; the report includes TTPs, network indicators and file hashes to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
