A new and highly aggressive strain of ransomware, dubbed Spirals, has been uncovered by researchers at Symantec’s Threat Hunter Team. This powerful threat not only encrypted a corporate network in under 24 hours but also displayed a chilling level of sophistication and speed. The attack, which occurred in June, targeted an IT services firm in South Asia, compromising an Internet Information Services (IIS) server exposed on the public web.
The Spirals operator moved swiftly after gaining initial access, uploading an ASP.NET web shell to create a backdoor into the network. Within hours, they bypassed User Account Control (UAC), enabled Remote Desktop, and created a local account to maintain persistent access. The attacker also dumped the SAM registry hive and LSASS process memory in an attempt to extract credentials, highlighting the importance of robust password policies and secure authentication mechanisms.
As the Spirals operator continued to move laterally through the network, they used Windows Management Instrumentation (WMI) to infect over a dozen systems. To maintain their hold on the network, they established redundant remote access channels using revsocks, Chisel, and Cloudflare tunnels. In preparation for the encryption stage, a PowerShell payload disabled Microsoft Defender, removed its threat definitions, and stopped services associated with various backup, database, and virtualization products.
The deployment of the Spirals ransomware payload occurred less than 24 hours after initial compromise, demonstrating the alarming speed at which modern threats can spread. The Spirals family uses AES-128 keys protected by an attacker-controlled ECDH P-256 public key for encryption. In a clever move to accelerate the process, it employs intermittent encryption for files larger than 5MB. A ransom note named RECOVERY_SECTION.log is dropped on the C:\ drive, containing instructions to negotiate a ransom and threatening public exposure of stolen data within six days if payment is not made.
While it remains unclear whether Spirals was intended for broader cybercrime deployment or created specifically for this attack at the IT services firm, Symantec’s report provides valuable insights into network indicators and file hashes associated with the threat. This information can be used by organizations worldwide to set up defenses against this threat group.
As we’ve seen time and again, speed is a key factor in modern cyber threats. In this case, Spirals operators moved swiftly from initial access to encryption, highlighting the importance of continuous monitoring and rapid incident response. To protect your organization from similar attacks, it’s essential to regularly test and validate security controls, including SIEM and EDR rules. This helps ensure that you’re not caught off guard by sophisticated threats like Spirals. By staying vigilant and proactive in your security posture, you can reduce the risk of a successful attack and minimize potential damage.
Source: Bleeping Computer — 2026-07-16