DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // SPIRALS-RANSOMWAREFIRST SEEN: JUN 2026

SPIRALS

ALSO KNOWN AS: Unknown operator — ransomware family name self-attributed
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (threat actor unidentified as of disclosure)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:JUN 2026
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL71/100
RESOURCES71/100
PERSISTENCE74/100
STEALTH66/100
IMPACT80/100

Documented by Symantec's Threat Hunter Team on July 16, 2026, Spirals is a previously unseen Rust-based ransomware family that struck a South Asian IT services company in June 2026, moving from initial IIS web shell upload to full network-wide encryption in under 24 hours. The ransomware uses per-file AES-128 keys wrapped with an attacker-controlled ECDH P-256 public key and deploys intermittent encryption on files over 5MB for speed. The sophistication of execution — including UAC bypass, SAM hive extraction, redundant tunneling via revsocks, Chisel, and Cloudflare Tunnels, and WMI-based lateral movement to over a dozen systems within minutes — suggests a technically capable operator likely to target more victims.

Financial extortion via double-extortion ransomware targeting IT services sector; rapid sub-24-hour breach-to-encryption operations

ASP.NET web shell on IIS (initial access), UAC bypass privilege escalation, SAM/LSASS credential dumping, WMI lateral movement, PsExec mass deployment, revsocks/Chisel/Cloudflare Tunnel covert C2, Windows Defender disablement, SYSVOL script directory payload placement, AES-128 + ECDH P-256 encryption, six-day data leak threat

IT SERVICES
MANAGED SERVICE PROVIDERS
SOUTH ASIA

ASP.NET IIS web shell, revsocks reverse SOCKS proxy, Chisel (renamed chrome.exe), Cloudflare Tunnel client, Tor-based negotiation portal, RECOVERY_SECTION.log ransom note, bitsadmin.exe payload masquerading

FILE DATE: JUN 2026
Spirals – South Asia IT Services Double Extortion
Debut attack on a South Asian IT services firm; compressed breach-to-encryption timeline to under 24 hours using automated lateral movement and redundant covert channels, threatening data publication within six days.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn