bleeping-computer · Crawled Jul 16, 2026
New Spirals ransomware encrypts victim network in under 24 hours
2 IoCs
Read original article ↗
AI Summary
A new ransomware actor named Spirals successfully breached an IT services firm in South Asia, achieving full network encryption within 24 hours of initial access. The attackers exploited a publicly exposed IIS server, deployed an ASP.NET web shell, and used tools like PsExec, revsocks, and Chisel for lateral movement and persistence. The Spirals ransomware, written in Rust, uses AES-128 encryption protected by ECDH P-256 and employs intermittent encryption to speed up the process, threatening victims with data exposure unless a ransom is paid.
AI-extracted · verify before operational use