Spirals Attackers Disable Windows Defender and Kill Backup Services Before Encrypting Systems

A newly identified ransomware family, Spirals, was used in a double-extortion attack against an IT services company in South Asia in June 2026.

Researchers from Symantec’s Threat Hunter Team said the Rust-based malware was deployed less than 24 hours after attackers gained access to the victim’s network.

The operation began with the compromise of an internet-facing Microsoft IIS web server. Attackers uploaded an ASP.NET web shell, giving them remote command execution through the IIS worker process.

During a rapid three-hour hands-on-keyboard session, they created persistence, escalated privileges, harvested credentials, disabled security products. They prepared the environment for widespread ransomware deployment.

The attackers used cmd.exe and PowerShell.exe through the compromised web server to execute commands. They bypassed User Account Control, enabled Remote Desktop Protocol, and created a local account for continued access.

They also enumerated users, network shares, installed software, and other systems that could be targeted later.

To collect credentials, the threat actors dumped the Windows Security Account Manager, or SAM, hive and saved it inside a password-protected archive.

They later used rundll32.exe with comsvcs.dll to dump LSASS memory on multiple systems. This activity may have exposed credentials for privileged domain accounts and enabled fast lateral movement.

The group used several tunneling and proxy tools to maintain covert access. These included reverse-SOCKS proxy tool revsocks, Chisel renamed as chrome.exe, and a Cloudflare Tunnel client.

The tools created redundant outbound channels, allowing the attackers to bypass network controls and access internal systems remotely.

Spirals Ransomware Silences Defenses

On June 17, the attackers used PsExec to run a base64-encoded PowerShell payload as SYSTEM on remote machines.

The payload first turned off Microsoft Defender real-time monitoring, removed threat definitions, and disabled IOAV protection before the ransomware execution phase.

The same script then searched for and forcibly stopped running services connected to backup, database, and virtualization products.

The targeted list included Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, SAP, Sage, Intuit, and Lotus Domino.

This step is designed to maximize ransomware impact. Stopping backup and database services can prevent open file handles from blocking encryption, while also weakening an organization’s ability to restore systems quickly.

It also creates operational disruption before the encryptor locks files across the network. The attackers moved at high speed.

One host reportedly used PsExec to deliver the same PowerShell payload to multiple remote targets every few seconds for about 30 minutes.

The targets included domain controllers, file servers, application servers, virtual machines, and workstations, indicating that the attackers had likely conducted Active Directory and network reconnaissance before launching the mass deployment, security said.

Indicators of Compromise

TypeIndicator (SHA256 / Name)Description
Ransomware binary0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141Spirals ransomware, observed as bitsadmin.exe, vbr2116.exe
Proxy tool4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649revsocks.exe reverse SOCKS proxy

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories