security-com · Crawled Jul 31, 2026
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
17 IoCs
Read original article ↗
AI Summary
A new Rust-based ransomware named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The attackers gained initial access via a compromised IIS web server and used an ASP.NET web shell to establish persistence, escalate privileges, and move laterally using WMI and PsExec. The ransomware, disguised as bitsadmin.exe, encrypted files using AES-128 keys wrapped with ECDH P-256, and threatened to leak stolen data via a Tor-based portal. Multiple tunneling tools and C2 infrastructure were used to maintain access and exfiltrate data.
AI-extracted · verify before operational use
Indicators of Compromise 17 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141 | Details → |
| SHA-256 | 4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244ccde649 | Details → |
| SHA-256 | 7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b | Details → |
| SHA-256 | 83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892 | Details → |
| SHA-256 | 84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d | Details → |
| SHA-256 | 862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1 | Details → |
| SHA-256 | b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556 | Details → |
| IP | 185[.]141[.]216[.]194 | Details → |
| Domain | computer[.]kplus[.]com | Details → |
| Domain | beta[.]padmin[.]com | Details → |
| Filename | bitsadmin.exe | Details → |
| Filename | vbr2116.exe | Details → |
| Filename | revsocks.exe | Details → |
| Filename | tunn.exe | Details → |
| Filename | chrome.exe | Details → |
| Filename | tokens.exe | Details → |
| Filename | cloudflared-windows-amd64.exe | Details → |