{"id":63843,"date":"2026-07-18T09:48:36","date_gmt":"2026-07-18T13:48:36","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=63843"},"modified":"2026-07-18T09:48:36","modified_gmt":"2026-07-18T13:48:36","slug":"spirals-ransomware-attack","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/spirals-ransomware-attack\/","title":{"rendered":"Spirals Ransomware Encrypts IT Firm Under 24 Hours via IIS Web Shell and PsExec"},"content":{"rendered":"<p>A previously unknown ransomware family designated &#8220;Spirals&#8221; achieved full network encryption within <a href=\"https:\/\/overcentral.com\/en\/citrixbleed-vulnerability-exploited-24-hours\/\" title=\"CitrixBleed Vulnerability Exploited Within 24 Hours of Disclosure\" data-iacss-internal=\"1\">24 hours<\/a> of the initial breach during a targeted attack against an IT services company in South Asia in June 2026. The Rust-based payload, which exhibits characteristics of either a purpose-built tool for this single operation or an entirely new family, leveraged a combination of web shell access, tunneling utilities, and enterprise deployment tools to move from initial compromise to domain-wide encryption with remarkable speed. The threat actor behind the operation has not been identified, but the technical discipline displayed suggests a highly skilled operator with pre-planned targeting.<\/p>\n<h2>Spirals Ransomware Attack Chain: IIS Web Shell to Domain-Wide Encryption<\/h2>\n<p>The intrusion began on June 16 at 22:21 local time when attackers compromised an internet-facing IIS web server and uploaded an ASP.NET web shell. Within minutes, three separate tunneling tools were deployed, including a Chisel instance disguised as <code>chrome.exe<\/code>codecodecodecode and a <a href=\"https:\/\/overcentral.com\/en\/cloudflare-precursor-bot-detection\/\" title=\"Cloudflare Expands Behavioral Tracking to Combat AI Bots\" data-iacss-internal=\"1\">Cloudflare<\/a> tunnel client that established redundant, covert communication channels. A token impersonation tool followed shortly after, enabling privilege escalation from the initial foothold.<\/p>\n<p>During a concentrated three-hour hands-on-keyboard session, the operator spawned <code>cmd.exe<\/code>codecodecodecode and <code>powershell.exe<\/code>codecodecodecode through the IIS worker process, performed a User Account Control bypass, enabled Remote Desktop Protocol, created a persistent local account, and dumped the SAM hive. By 23:07, precursor activity showed active attempts to disable security tools, signaling the transition from reconnaissance to active defense evasion.<\/p>\n<h2>Lateral Movement and Automated Deployment<\/h2>\n<p>The attackers pivoted to WMI-based lateral movement at 23:33, successfully compromising over a dozen machines within minutes using compromised domain administrator credentials. The rapid cadence strongly suggests automated, pre-planned targeting rather than manual network exploration. On June 17, the attackers shifted tactics to PsExec as their primary mass deployment vector. Starting around 14:12, a single compromised host pushed an identical base64-encoded PowerShell payload to network targets every few seconds for roughly 30 minutes.<\/p>\n<p>This automated payload immediately disabled <a href=\"https:\/\/overcentral.com\/en\/microsoft-defender-patch-disk-exhaustion\/\" title=\"Microsoft Defender patch risks filling Windows hard drives\" data-iacss-internal=\"1\">Windows<\/a> Defender&#8217;s real-time monitoring and forcibly stopped over 20 critical backup, database, and virtualization services, including Veeam, VMware, SQL Server, and Exchange, effectively clearing open file handles ahead of encryption. The ransomware executable itself was named <code>bitsadmin.exe<\/code>codecodecodecode to masquerade as a legitimate <a href=\"https:\/\/www.microsoft.com\/windows\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Windows<\/a> utility. It was staged across multiple network locations, including the SYSVOL domain scripts directory, ensuring automated propagation even to machines not directly targeted by the PsExec script.<\/p>\n<h2>What Is Spirals Ransomware and How Does It Work?<\/h2>\n<p>Spirals is a full-featured, Rust-based encryptor built with defense evasion, automated lateral movement, process termination, and privilege escalation capabilities. The ransomware uses a per-file AES-128 symmetric key to secure the raw block data of targeted files, wrapped with an attacker-controlled ECDH P-256 public key to protect the local AES keys from decryption. For files over 5 MB, the encryptor employs intermittent encryption of jittered chunks to speed up the locking cycle, a technique that reduces the time required to encrypt large volumes of data while maintaining an effective denial of access.<\/p>\n<p>The ransomware leaves a local footprint to force negotiation: the ransom note is dropped across the system as <code>C:\\RECOVERY_SECTION.log<\/code>codecodecodecode. It threatens the public leak of stolen corporate data within six days if the target fails to pay. The note directs victims to a Tor negotiation portal, which Symantec confirmed explicitly names the threat family as &#8220;Spirals&#8221;.<\/p>\n<h2>Defensive Priorities for Organizations Facing Similar Threats<\/h2>\n<p>While Spirals has only been observed against a single victim so far, its operational discipline signals a highly skilled actor capable of rapidly scaling attacks. The combination of layered tunneling infrastructure, credential harvesting via LSASS dumps using <code>rundll32.exe<\/code>codecodecodecode and <code>comsvcs.dll<\/code>codecodecodecode, and domain-wide propagation via SYSVOL requires an immediate defensive response. Symantec&#8217;s indicator list includes dedicated staging infrastructure hosted at <code>185.141.216.194<\/code>codecodecodecode alongside two compromised domains used for hosting malicious payloads.<\/p>\n<p>Organizations running internet-facing IIS servers should enforce the following priorities:<\/p>\n<ul>\n<li><strong>Web Shell Detection:<\/strong> Actively monitor internet-facing web servers for unauthenticated ASP.NET file modifications or sudden process creations originating from IIS worker loops.<\/li>\n<li><strong>Behavioral Auditing:<\/strong> Set immediate alerts on anomalous WMI and PsExec activity executing rapid, sequential connection attempts across internal zones.<\/li>\n<li><strong>Credential Protection:<\/strong> Harden endpoints against LSASS memory dumping tools and tightly restrict domain administrator account usage on non-domain controllers.<\/li>\n<\/ul>\n<h2>What Affected Organizations Should Do Now<\/h2>\n<p>Any organization that suspects exposure to similar attack vectors should immediately audit all internet-facing IIS servers for unauthorized web shells, review domain administrator account activity for anomalous lateral movement patterns, and ensure that backup systems are isolated from the production network with immutable storage. Deploying a multi-layered endpoint protection solution with behavioral analysis capabilities can help detect and block the type of rapid, automated deployment techniques used in this attack. Additionally, implementing strict application control policies to prevent unauthorized executables from running, particularly those masquerading as legitimate system utilities, can reduce the risk of similar ransomware deployment. Finally, organizations should conduct a thorough review of SYSVOL and other domain controller shares for unauthorized binaries, as this attack demonstrated the effectiveness of using legitimate infrastructure paths for payload staging.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A previously unknown ransomware family designated &#8220;Spirals&#8221; achieved full network encryption within 24 hours of the initial breach during a targeted attack against an IT services company in South Asia in June 2026. The Rust-based payload, which exhibits characteristics of either a purpose-built tool for this single operation or an entirely new family, leveraged a [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84522,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/63843.png","fifu_image_alt":"Spirals Ransomware Encrypts IT Firm Under 24 Hours via IIS Web Shell","footnotes":""},"categories":[349],"tags":[],"class_list":["post-63843","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/63843.png","fifu_image_alt":"Spirals Ransomware Encrypts IT Firm Under 24 Hours via IIS Web Shell","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63843","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=63843"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63843\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84522"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=63843"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=63843"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=63843"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}