Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

0
Medium
Published: 07/16/2026 (07/16/2026, 11:39:23 UTC)
Source: AlienVault OTX General

Description

A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 12:41:17 UTC

Technical Analysis

The Spirals ransomware is a newly discovered Rust-based malware family deployed in a targeted double extortion attack against a South Asian IT services company. Attackers gained initial access through a compromised internet-facing IIS web server by leveraging an ASP.NET web shell. Within 24 hours, they escalated privileges, moved laterally across the network using PsExec, and deployed ransomware that encrypts files using AES-128 keys. The attackers also harvested credentials by dumping the SAM hive and LSASS process memory, disabled endpoint security, and established persistence using multiple tunneling tools and reverse-SOCKS proxies for stealthy command-and-control communications. The ransomware campaign included threats to publish stolen data within six days, indicating a double extortion tactic. The attack demonstrates high operational security and advanced techniques, though the threat actor has not been identified.

Potential Impact

The ransomware encrypts files across the victim network using AES-128 encryption, causing data unavailability. Additionally, the attackers exfiltrated data and threatened to publish it within six days, increasing pressure on the victim through double extortion. The attack involved disabling endpoint security and harvesting credentials, which could facilitate further compromise or persistence. The rapid deployment and advanced evasion techniques indicate a high level of operational sophistication, potentially enabling widespread impact if leveraged in future campaigns.

Defensive Guidance

No specific patch or remediation is indicated for this ransomware family. Organizations should focus on detecting and preventing initial access vectors such as compromised IIS web servers and ASP.NET web shells. Monitoring for unusual lateral movement tools like PsExec, credential dumping activities, and tunneling tools can aid detection. Endpoint security solutions should be kept updated and configured to detect suspicious behavior. Since this is a targeted ransomware campaign, incident response should include isolating infected systems promptly and restoring from clean backups. There is no vendor patch or official fix for the ransomware itself. Patch status is not yet confirmed — check vendor advisories for any updates on detection or mitigation tools.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.security.com/threat-intelligence/ransomware-spirals-extortion"]
Adversary
null
Pulse Id
6a58c2ecd43c8e98d4bdd2e0
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip185.141.216.194

Hash

ValueDescriptionCopy
hash26a15a6a9bea58e9ad2ada9a6c8606b5
hashe25c56bd13eff7280e493bf58501c47891fe63bf
hash0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141
hash4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649
hash7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b
hash83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892
hash84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d
hash862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1
hashb5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556

Url

ValueDescriptionCopy
urlhttps://beta.padmin.com/mybenefits/Templates/cd.zip
urlhttps://computer.kplus.com/cd.zip

Domain

ValueDescriptionCopy
domainbeta.padmin.com
domaincomputer.kplus.com

Threat ID: 6a59782068715ace4305c1a8

Added to database: 07/17/2026, 00:32:32 UTC

Last enriched: 08/15/2026, 12:41:17 UTC

Last updated: 08/31/2026, 02:31:02 UTC

Views: 252

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses