logo

Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

ID: 693e7632-e492-5d86-aad3-a50fbca90f9c

STIX ID: report--693e7632-e492-5d86-aad3-a50fbca90f9c

Feed Name: security.com

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-20

Author: Threat Hunter Team

...
...

A previously unseen Rust-based ransomware family called “Spirals” was used in a June 2026 double-extortion attack against an IT services company: attackers gained access by uploading an ASP.NET web shell to an IIS server, performed rapid hands-on-keyboard activity (UAC bypass, RDP enablement, SAM and LSASS credential dumps), deployed multiple tunneling tools and covert C2 channels, and pushed the ransomware broadly via PsExec and replicated locations (including SYSVOL), encrypting files and threatening to leak stolen data; the report includes technical TTPs and IOCs (hashes, IPs, and download URLs) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.