Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified.
AI Analysis
Technical Summary
The Spirals ransomware is a newly discovered Rust-based malware family deployed in a targeted double extortion attack against a South Asian IT services company. Attackers gained initial access through a compromised internet-facing IIS web server by leveraging an ASP.NET web shell. Within 24 hours, they escalated privileges, moved laterally across the network using PsExec, and deployed ransomware that encrypts files using AES-128 keys. The attackers also harvested credentials by dumping the SAM hive and LSASS process memory, disabled endpoint security, and established persistence using multiple tunneling tools and reverse-SOCKS proxies for stealthy command-and-control communications. The ransomware campaign included threats to publish stolen data within six days, indicating a double extortion tactic. The attack demonstrates high operational security and advanced techniques, though the threat actor has not been identified.
Potential Impact
The ransomware encrypts files across the victim network using AES-128 encryption, causing data unavailability. Additionally, the attackers exfiltrated data and threatened to publish it within six days, increasing pressure on the victim through double extortion. The attack involved disabling endpoint security and harvesting credentials, which could facilitate further compromise or persistence. The rapid deployment and advanced evasion techniques indicate a high level of operational sophistication, potentially enabling widespread impact if leveraged in future campaigns.
Mitigation Recommendations
No specific patch or remediation is indicated for this ransomware family. Organizations should focus on detecting and preventing initial access vectors such as compromised IIS web servers and ASP.NET web shells. Monitoring for unusual lateral movement tools like PsExec, credential dumping activities, and tunneling tools can aid detection. Endpoint security solutions should be kept updated and configured to detect suspicious behavior. Since this is a targeted ransomware campaign, incident response should include isolating infected systems promptly and restoring from clean backups. There is no vendor patch or official fix for the ransomware itself. Patch status is not yet confirmed — check vendor advisories for any updates on detection or mitigation tools.
Indicators of Compromise
- ip: 185.141.216.194
- hash: 26a15a6a9bea58e9ad2ada9a6c8606b5
- hash: e25c56bd13eff7280e493bf58501c47891fe63bf
- hash: 0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141
- hash: 4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649
- hash: 7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b
- hash: 83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892
- hash: 84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d
- hash: 862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1
- hash: b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556
- url: https://beta.padmin.com/mybenefits/Templates/cd.zip
- url: https://computer.kplus.com/cd.zip
- domain: beta.padmin.com
- domain: computer.kplus.com
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
Description
A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Spirals ransomware is a newly discovered Rust-based malware family deployed in a targeted double extortion attack against a South Asian IT services company. Attackers gained initial access through a compromised internet-facing IIS web server by leveraging an ASP.NET web shell. Within 24 hours, they escalated privileges, moved laterally across the network using PsExec, and deployed ransomware that encrypts files using AES-128 keys. The attackers also harvested credentials by dumping the SAM hive and LSASS process memory, disabled endpoint security, and established persistence using multiple tunneling tools and reverse-SOCKS proxies for stealthy command-and-control communications. The ransomware campaign included threats to publish stolen data within six days, indicating a double extortion tactic. The attack demonstrates high operational security and advanced techniques, though the threat actor has not been identified.
Potential Impact
The ransomware encrypts files across the victim network using AES-128 encryption, causing data unavailability. Additionally, the attackers exfiltrated data and threatened to publish it within six days, increasing pressure on the victim through double extortion. The attack involved disabling endpoint security and harvesting credentials, which could facilitate further compromise or persistence. The rapid deployment and advanced evasion techniques indicate a high level of operational sophistication, potentially enabling widespread impact if leveraged in future campaigns.
Defensive Guidance
No specific patch or remediation is indicated for this ransomware family. Organizations should focus on detecting and preventing initial access vectors such as compromised IIS web servers and ASP.NET web shells. Monitoring for unusual lateral movement tools like PsExec, credential dumping activities, and tunneling tools can aid detection. Endpoint security solutions should be kept updated and configured to detect suspicious behavior. Since this is a targeted ransomware campaign, incident response should include isolating infected systems promptly and restoring from clean backups. There is no vendor patch or official fix for the ransomware itself. Patch status is not yet confirmed — check vendor advisories for any updates on detection or mitigation tools.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.security.com/threat-intelligence/ransomware-spirals-extortion"]
- Adversary
- null
- Pulse Id
- 6a58c2ecd43c8e98d4bdd2e0
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip185.141.216.194 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash26a15a6a9bea58e9ad2ada9a6c8606b5 | — | |
hashe25c56bd13eff7280e493bf58501c47891fe63bf | — | |
hash0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141 | — | |
hash4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649 | — | |
hash7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b | — | |
hash83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892 | — | |
hash84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d | — | |
hash862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1 | — | |
hashb5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://beta.padmin.com/mybenefits/Templates/cd.zip | — | |
urlhttps://computer.kplus.com/cd.zip | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainbeta.padmin.com | — | |
domaincomputer.kplus.com | — |
Threat ID: 6a59782068715ace4305c1a8
Added to database: 07/17/2026, 00:32:32 UTC
Last enriched: 08/15/2026, 12:41:17 UTC
Last updated: 08/31/2026, 02:31:02 UTC
Views: 252
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.