News Room
16
Share
Spirals Ransomware: New Rust-Based Actor Executes Full Corporate Intrusion in Under 24 Hours
highThreat Intelligence

Spirals Ransomware: New Rust-Based Actor Executes Full Corporate Intrusion in Under 24 Hours

Symantec has identified 'Spirals,' a sophisticated new ransomware group using Rust-based payloads and rapid exfiltration tactics. The group recently compromised a South Asian IT firm, moving from initial access to full encryption in less than a day.

17 July 2026Last updated 20 August 20265 min readSymantec Threat Hunter Team
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
High
Actor Type:
Ransomware Group
Geography:
South Asia
Confidence:
High Confidence
Source:
Symantec Threat Hunter Team
Read Time:
5 min

Executive Summary

On July 16, 2026, cybersecurity researchers at the Symantec Threat Hunter Team released a detailed analysis of a previously undocumented ransomware actor dubbed 'Spirals.' This group has demonstrated an alarming level of operational efficiency, completing a complex corporate intrusion—including initial access, lateral movement, data exfiltration, and system-wide encryption—in less than 24 hours. The primary victim identified was a large IT services firm located in South Asia, suggesting the group may currently be targeting service providers to maximize the impact of their extortion attempts. Spirals utilizes a custom-built Rust encryptor, reflecting a broader trend in the threat landscape toward memory-safe languages that complicate traditional signature-based detection.

Threat Analysis

The Spirals attack chain begins with the exploitation of exposed Internet Information Services (IIS) servers. In the documented case, the attackers gained entry by leveraging an unpatched vulnerability on a public-facing web server, followed immediately by the deployment of an ASP.NET-based web shell. Once the foothold was established, the threat actor demonstrated high proficiency in Windows environment manipulation. They successfully bypassed User Account Control (UAC), enabled Remote Desktop Protocol (RDP) for persistence, and created local administrative accounts. To facilitate data theft and lateral movement, Spirals leveraged a suite of open-source and legitimate tools, including Chisel, revsocks, and Cloudflare tunnels, to establish redundant, encrypted communication channels that bypassed standard egress filtering.

Technical Details

The core of the operation is the Spirals ransomware payload, which is frequently masqueraded as 'bitsadmin.exe' to blend in with legitimate Background Intelligent Transfer Service (BITS) activity. The malware is written in Rust and employs a sophisticated encryption scheme involving AES-128 keys protected by an attacker-controlled Elliptic Curve Diffie-Hellman (ECDH) P-256 public key. To optimize the speed of the attack, Spirals utilizes intermittent encryption for any files larger than 5MB, a technique that significantly reduces the time required to lock large databases and virtual machine disks. Before the encryption phase, the operator executes a PowerShell script that terminates 23 specific services related to backups, databases, and virtualization platforms such as Veeam, VMware, and SQL Server. This ensures that the ransomware has exclusive access to critical files and prevents easy recovery from local backups.

Attribution Assessment

Attribution for Spirals remains tentative. While the speed and technical precision of the attack suggest an experienced group of operators, researchers have not yet found definitive overlaps with known Advanced Persistent Threat (APT) groups or established Ransomware-as-a-Service (RaaS) operations like LockBit or BlackSuit. The use of an extortion portal and the threat to leak data within six days are hallmarks of professional cybercriminal organizations. However, the limited number of observed cases suggests that Spirals may still be in a testing or private-affiliate phase, or alternatively, that it is a highly selective group conducting bespoke operations against high-value targets.

Implications

The emergence of Spirals underscores the shrinking 'window of opportunity' for defenders. A sub-24-hour dwell time means that traditional daily security reviews are insufficient to prevent encryption. Furthermore, the adoption of Rust-based malware continues to challenge automated analysis tools. The group's choice of an IT services firm as a primary target indicates a potential 'supply chain' motive, where access to the provider's network could lead to downstream access to multiple clients, amplifying the extortion pressure.

Recommendations

Encrygma recommends the following immediate actions to mitigate the risk posed by Spirals and similar rapid-action ransomware groups:

  1. Harden Perimeter Services: Ensure all public-facing IIS and web servers are fully patched and configured to follow the principle of least privilege.
  2. Monitor BITS Activity: Implement behavioral alerts for unusual executions of bitsadmin.exe, particularly those originating from accounts that do not typically manage system updates.
  3. Restrict Tunneling Tools: Audit environments for the presence of tools like Chisel, Cloudflare Tunnels, and revsocks. Block unauthorized use via EDR and Application Control policies.
  4. Enforce MFA: Deploy Multi-Factor Authentication on all remote access points, including RDP and VPNs, to prevent credential reuse following LSASS memory dumps.
  5. Endpoint Protection: Ensure EDR solutions are configured to detect unauthorized PowerShell scripts that attempt to stop database and backup services.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo