Spirals
Spirals is a previously unseen Rust-based ransomware family observed in a June 2026 double-extortion intrusion against an IT services company in South Asia.
Profile source: Mallory opens in a new tabSpirals
Family profile
Spirals is a previously unseen Rust-based ransomware family observed in a June 2026 double-extortion intrusion against an IT services company in South Asia. In the documented case, the operators compromised an internet-facing Microsoft IIS server, deployed an ASP.NET web shell, and rapidly progressed through hands-on-keyboard post-compromise activity to enterprise-wide encryption in less than 24 hours. The intrusion included privilege escalation via UAC bypass, credential theft through SAM and LSASS dumping, persistence through local account creation and remote access enablement, and lateral movement using WMI and PsExec. The operators also established covert access channels with tunneling and proxy tooling and disabled or impaired defenses before encryption by turning off Microsoft Defender protections and stopping backup, database, and virtualization services. Spirals encrypts files with a unique AES-128 key per file, with each key protected using an attacker-controlled ECDH P-256 public key, and uses intermittent encryption on larger files to accelerate impact. The operation followed a double-extortion model, combining file encryption with data theft and threats to publish stolen information within days if payment was not made. Attribution to a known threat actor has not been established, and public reporting has so far tied Spirals to a single victim environment, though the operators were assessed as skilled and capable of broader campaigns.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Lateral Movement
- Persistence
- Post Exploitation
- Privilege Escalation
- Process Injection
Operational record
Recent claims
MITRE ATT&CK
Spirals in ATT&CK
35 distinct techniquesReporting
Research mentioning Spirals
Spirals Ransomware Encrypts a Network in Under 24 Hours
A previously unseen Rust-based ransomware family dubbed Spirals was used in a double-extortion attack against an IT services company in South Asia, with attackers moving from initial compromise to network-wide encryption in under 24 hours. Investigators said the intrusion began through a publicly exposed IIS web server, where the attackers deployed an ASP.NET web shell, then quickly established persistence, harvested credentials, escalated access, disabled security tools, and moved laterally across the environment. The operators maintained covert access through multiple channels including RDP, revsocks, Chisel, and Cloudflare Tunnel, and pushed the ransomware broadly with PsExec and WMI. Symantec said Spirals encrypts files using AES-128 with an attacker-controlled ECDH P-256 public key, uses intermittent encryption for files larger than 5 MB, and drops a ransom note at C:\RECOVERY_SECTION.log; the note warned that stolen data would be published within six days if payment was not made. Researchers described the attack as notably fast and stealthy, while noting only one Spirals incident has been observed so far.