News Room
16
Share
New 'Spirals' Ransomware Variant Achieves Full-Network Encryption in Under 24 Hours
criticalThreat Intelligence

New 'Spirals' Ransomware Variant Achieves Full-Network Encryption in Under 24 Hours

A newly identified threat actor dubbed 'Spirals' has executed a high-speed corporate intrusion, moving from initial access to full-network encryption in less than 24 hours using a sophisticated Rust-based payload.

16 July 2026Last updated 20 August 20265 min readSymantec Threat Hunter Team
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
South Asia
Confidence:
High Confidence
Source:
Symantec Threat Hunter Team
Read Time:
5 min

Executive Summary

On July 16, 2026, threat intelligence researchers identified a highly efficient new ransomware operation named 'Spirals.' The group recently successfully breached a major IT services provider in South Asia, completing the entire attack lifecycle—from initial entry to data exfiltration and final encryption—in under 24 hours. This level of speed suggests a highly automated workflow and a high degree of operator proficiency. The attack highlights a growing trend of compressed 'dwell times' in modern ransomware-as-a-service (RaaS) campaigns.

Threat Analysis

The Spirals group utilizes a double-extortion model, where data is exfiltrated to a dedicated leak site (DLS) before the environment is locked. The initial access was gained through an unpatched vulnerability in an Internet Information Services (IIS) server exposed to the public web. Unlike traditional groups that may spend days or weeks in reconnaissance, Spirals moves immediately to lateral movement and credential harvesting. Their primary objective appears to be large-scale corporate environments where IT service dependency can be leveraged for maximum pressure.

Technical Details

Upon gaining access to the IIS server, the attackers deployed an ASP.NET web shell to establish a foothold. Within three hours, the operator bypassed User Account Control (UAC) and enabled Remote Desktop (RDP) to facilitate interactive access. Credential harvesting was conducted by dumping the Security Account Manager (SAM) registry hive and the Local Security Authority Subsystem Service (LSASS) memory.

Lateral movement was achieved using Windows Management Instrumentation (WMI) and PsExec, targeting over a dozen critical systems. To ensure successful encryption, the group utilized a custom PowerShell script to disable Microsoft Defender and terminate services for 23 different backup, database, and virtualization products, including VMware, Veeam, and SQL Server. The final payload, written in Rust and named 'bitsadmin.exe' to masquerade as a legitimate Windows utility, uses AES-128 encryption with keys protected by ECDH P-256. Notably, the ransomware employs intermittent encryption for files larger than 5MB to drastically increase the speed of the locking process.

Attribution Assessment

Attribution for Spirals remains tentative, though the group’s infrastructure and tactics suggest a well-funded cybercriminal collective. While the use of Rust is common among modern Russian-speaking groups (like BlackCat/ALPHV and BlackSuit), the specific focus on South Asian IT targets and the rapid automated nature of the deployment suggest a possible evolution or offshoot of existing RaaS ecosystems. The group's ransom note, titled 'RECOVERY_SECTION.log,' points victims to a Tor-based communication portal.

Implications

The emergence of Spirals signals a dangerous shift toward 'speed-run' ransomware attacks. By reducing the dwell time to less than a single workday, the group effectively bypasses many traditional human-in-the-loop security monitoring services. For IT service providers, the threat is amplified by the risk of downstream compromise of their own clients, making Spirals a significant supply-chain threat.

Recommendations

To defend against the Spirals variant, organizations should prioritize the following:

  1. Aggressive Patching: Ensure all public-facing IIS and web servers are patched against known RCE vulnerabilities.
  2. Endpoint Defense: Implement 'tamper protection' in EDR solutions to prevent the unauthorized disabling of security services via PowerShell.
  3. Network Segmentation: Limit the use of WMI and PsExec between workstations and sensitive servers to impede lateral movement.
  4. Credential Guarding: Enable Windows Defender Credential Guard to prevent LSASS memory dumping.
  5. Accelerated Incident Response: Shift response playbooks to favor immediate isolation of systems upon detection of web shell activity or unusual RDP enablement.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo