A New Ransomware Actor Emerges, Breaching Networks in Record Time
In a disturbing display of speed and sophistication, a new ransomware actor known as Spirals has successfully compromised an IT services firm’s network in South Asia, completing the entire attack from initial access to data theft and encryption in under 24 hours. This alarming pace highlights the evolving threat landscape, where attackers are becoming increasingly efficient in their operations.
The breach began with the compromise of an Internet Information Services (IIS) server exposed on the public web. Researchers at Symantec’s Threat Hunter Team detail how the attacker quickly uploaded an ASP.NET web shell, which allowed them to bypass User Account Control (UAC) and establish a persistent presence on the network. The Spirals operator then created a local account, enabled Remote Desktop, and dumped sensitive information such as credentials.
The attack’s pace was relentless, with the threat actor attempting to remove security software on the hosts, using Windows Management Instrumentation (WMI) to move laterally across multiple systems, and establishing redundant remote access channels. A PowerShell payload disabled Microsoft Defender, removed its threat definitions, and halted services associated with various backup, database, and virtualization products.
The deployment of the Spirals ransomware payload, bitsadmin.exe, occurred less than 24 hours after initial compromise, demonstrating the group’s agility and determination. The malware uses AES-128 keys protected by an attacker-controlled ECDH P-256 public key and employs intermittent encryption for files larger than 5MB to accelerate the process.
The Spirals ransomware drops a ransom note named RECOVERY_SECTION.log on the C:\ drive, threatening victims with public exposure of stolen data within six days unless payment is made. However, it’s unclear whether this new family is intended for broader cybercrime deployment or if it was a custom payload created specifically for this attack.
This incident serves as a stark reminder that cybersecurity threats are becoming increasingly sophisticated and fast-paced. As organizations worldwide struggle to stay ahead of these attacks, it’s essential to prioritize network security and implement robust defenses. By doing so, businesses can reduce the risk of falling victim to such rapid and devastating breaches.
Source: Bleeping Computer — 2026-07-16