SUBJECT PROFILE
Documented by Symantec's Threat Hunter Team on July 16, 2026, Spirals is a previously unseen Rust-based ransomware family that struck a South Asian IT services company in June 2026, moving from initial IIS web shell upload to full network-wide encryption in under 24 hours. The ransomware uses per-file AES-128 keys wrapped with an attacker-controlled ECDH P-256 public key and deploys intermittent encryption on files over 5MB for speed. The sophistication of execution — including UAC bypass, SAM hive extraction, redundant tunneling via revsocks, Chisel, and Cloudflare Tunnels, and WMI-based lateral movement to over a dozen systems within minutes — suggests a technically capable operator likely to target more victims.
Financial extortion via double-extortion ransomware targeting IT services sector; rapid sub-24-hour breach-to-encryption operations
OPERATIONAL HISTORY
ASP.NET web shell on IIS (initial access), UAC bypass privilege escalation, SAM/LSASS credential dumping, WMI lateral movement, PsExec mass deployment, revsocks/Chisel/Cloudflare Tunnel covert C2, Windows Defender disablement, SYSVOL script directory payload placement, AES-128 + ECDH P-256 encryption, six-day data leak threat
KNOWN INFRASTRUCTURE
ASP.NET IIS web shell, revsocks reverse SOCKS proxy, Chisel (renamed chrome.exe), Cloudflare Tunnel client, Tor-based negotiation portal, RECOVERY_SECTION.log ransom note, bitsadmin.exe payload masquerading