A newly identified ransomware family, Spirals, was used in a double-extortion attack against an IT services company in South Asia in June 2026.
Researchers from Symantec’s Threat Hunter Team said the Rust-based malware was deployed less than 24 hours after attackers gained access to the victim’s network.
The operation began with the compromise of an internet-facing Microsoft IIS web server. Attackers uploaded an ASP.NET web shell, giving them remote command execution through the IIS worker process.
During a rapid three-hour hands-on-keyboard session, they created persistence, escalated privileges, harvested credentials, disabled security products. They prepared the environment for widespread ransomware deployment.
The attackers used cmd.exe and PowerShell.exe through the compromised web server to execute commands. They bypassed User Account Control, enabled Remote Desktop Protocol, and created a local account for continued access.
They also enumerated users, network shares, installed software, and other systems that could be targeted later.
To collect credentials, the threat actors dumped the Windows Security Account Manager, or SAM, hive and saved it inside a password-protected archive.
They later used rundll32.exe with comsvcs.dll to dump LSASS memory on multiple systems. This activity may have exposed credentials for privileged domain accounts and enabled fast lateral movement.
The group used several tunneling and proxy tools to maintain covert access. These included reverse-SOCKS proxy tool revsocks, Chisel renamed as chrome.exe, and a Cloudflare Tunnel client.
The tools created redundant outbound channels, allowing the attackers to bypass network controls and access internal systems remotely.
Spirals Ransomware Silences Defenses
On June 17, the attackers used PsExec to run a base64-encoded PowerShell payload as SYSTEM on remote machines.
The payload first turned off Microsoft Defender real-time monitoring, removed threat definitions, and disabled IOAV protection before the ransomware execution phase.
The same script then searched for and forcibly stopped running services connected to backup, database, and virtualization products.
The targeted list included Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, SAP, Sage, Intuit, and Lotus Domino.
This step is designed to maximize ransomware impact. Stopping backup and database services can prevent open file handles from blocking encryption, while also weakening an organization’s ability to restore systems quickly.
It also creates operational disruption before the encryptor locks files across the network. The attackers moved at high speed.
One host reportedly used PsExec to deliver the same PowerShell payload to multiple remote targets every few seconds for about 30 minutes.
The targets included domain controllers, file servers, application servers, virtual machines, and workstations, indicating that the attackers had likely conducted Active Directory and network reconnaissance before launching the mass deployment, security said.
Indicators of Compromise
| Type | Indicator (SHA256 / Name) | Description |
|---|---|---|
| Ransomware binary | 0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141 | Spirals ransomware, observed as bitsadmin.exe, vbr2116.exe |
| Proxy tool | 4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649 | revsocks.exe reverse SOCKS proxy |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs