Skip to content

Spirals

Spirals is a previously unseen Rust-based ransomware family observed in a June 2026 double-extortion intrusion against an IT services company in South Asia.

Profile source: Mallory opens in a new tab

Spirals

Family profile

Spirals is a previously unseen Rust-based ransomware family observed in a June 2026 double-extortion intrusion against an IT services company in South Asia. In the documented case, the operators compromised an internet-facing Microsoft IIS server, deployed an ASP.NET web shell, and rapidly progressed through hands-on-keyboard post-compromise activity to enterprise-wide encryption in less than 24 hours. The intrusion included privilege escalation via UAC bypass, credential theft through SAM and LSASS dumping, persistence through local account creation and remote access enablement, and lateral movement using WMI and PsExec. The operators also established covert access channels with tunneling and proxy tooling and disabled or impaired defenses before encryption by turning off Microsoft Defender protections and stopping backup, database, and virtualization services. Spirals encrypts files with a unique AES-128 key per file, with each key protected using an attacker-controlled ECDH P-256 public key, and uses intermittent encryption on larger files to accelerate impact. The operation followed a double-extortion model, combining file encryption with data theft and threats to publish stolen information within days if payment was not made. Attribution to a known threat actor has not been established, and public reporting has so far tied Spirals to a single victim environment, though the operators were assessed as skilled and capable of broader campaigns.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection

Operational record

Recent claims

MITRE ATT&CK

Spirals in ATT&CK

35 distinct techniques

Reporting

Research mentioning Spirals

Jul 22
Security Online Info

Spirals Ransomware Encrypts a Network in Under 24 Hours

A previously unseen Rust-based ransomware family dubbed Spirals was used in a double-extortion attack against an IT services company in South Asia, with attackers moving from initial compromise to network-wide encryption in under 24 hours. Investigators said the intrusion began through a publicly exposed IIS web server, where the attackers deployed an ASP.NET web shell, then quickly established persistence, harvested credentials, escalated access, disabled security tools, and moved laterally across the environment. The operators maintained covert access through multiple channels including RDP, revsocks, Chisel, and Cloudflare Tunnel, and pushed the ransomware broadly with PsExec and WMI. Symantec said Spirals encrypts files using AES-128 with an attacker-controlled ECDH P-256 public key, uses intermittent encryption for files larger than 5 MB, and drops a ransom note at C:\RECOVERY_SECTION.log; the note warned that stolen data would be published within six days if payment was not made. Researchers described the attack as notably fast and stealthy, while noting only one Spirals incident has been observed so far.

Jul 20
Gurucul Threat Research

Spirals: New Stealthy Ransomware Deployed Against Asian IT Company | Community Portal | Gurucul

Jul 20
Cyberveille

Nouveau ransomware Spirals déployé en double extorsion contre une entreprise IT en Asie du Sud | CyberVeille

Jul 19
Cyberthrone

Spirals Ransomware Dissection - TheCyberThrone

Jul 18
Cyber Security News

New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

Jul 17
Help Net Security

Spirals ransomware locks down victim systems in under 24 hours - Help Net Security

Jul 16
Scworld

Attackers execute a complete ransomware operation in under 24 hours | news | SC Media

Jul 16
Bleeping Computer

New Spirals ransomware encrypts victim network in under 24 hours

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.