Spirals: The Ransomware That Doesn't Wait

Amber | Attack
Download Now
Spirals: The Ransomware That Doesn't Wait | TA2026204 | HivePro Threat Advisory

Threat Advisory • Attack Report • TLP: Amber

Spirals: The Ransomware That Doesn't Wait

A previously undocumented Rust-based ransomware family, Spirals, moved from initial access on an internet-facing Microsoft IIS server to network-wide encryption in under 24 hours, striking an IT services organization in South Asia with a double-extortion ransomware operation.

Malware: Spirals Ransomware Double Extortion TLP: Amber Admiralty Code: A1 TA2026204
First Seen
June 16, 2026
Targeted Region
South Asia
Targeted Platform
Windows
Targeted Industry
IT Services
Malware
Spirals
Attack Type
Ransomware
Admiralty Code
A1
Date of Publication
July 17, 2026
TA Number
TA2026204

Summary

Spirals is a previously undocumented, Rust-based ransomware family deployed against an IT services company in South Asia in June 2026. First seen on June 16, 2026, the Spirals operators completed the entire intrusion — from initial access via an ASP.NET web shell on an internet-facing Microsoft IIS server to network-wide encryption using PsExec — in less than 24 hours, demonstrating an unusually rapid ransomware attack lifecycle.

The Spirals ransomware payload encrypts files using per-file AES-128 keys wrapped with an attacker-controlled ECDH P-256 public key, and applies intermittent encryption to files larger than 5 MB to accelerate the encryption process. The Spirals operation enforces a double-extortion model, threatening to publish stolen data on a Tor negotiation portal within a 6-day deadline if the ransom is not paid.

Targeted platforms and products in this Spirals ransomware attack include Microsoft IIS, ASP.NET, Microsoft Windows Defender, Microsoft Exchange, Microsoft Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, Microsoft SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino, reflecting the breadth of backup, database, virtualization, and business applications the Spirals operators disabled or targeted prior to encryption.


Attack Details

#1 Initial Access via IIS Web Shell and Tunneling

The Spirals operators gained initial access on June 16, 2026, by compromising an internet-facing Microsoft IIS web server and uploading an ASP.NET web shell. Through the IIS worker process, they spawned cmd.exe and PowerShell to run an interactive, hands-on-keyboard session. Within the first ten minutes, the Spirals operators deployed three network tunneling utilities — revsocks, Chisel, and a Cloudflare Tunnel client — under legitimate-looking directories to establish redundant encrypted outbound channels.

#2 Privilege Escalation and Defense Evasion

The operator bypassed User Account Control for local privilege escalation, enabled Remote Desktop Protocol, and created a local account for persistence. A token impersonation tool was used to acquire further elevated privileges, and endpoint security tools were targeted for uninstallation. Additional Spirals-related payloads were retrieved from external staging infrastructure, in some cases disguised with .jpg extensions to bypass content inspection.

#3 Credential Access and Lateral Movement

Credentials were harvested by dumping the Security Account Manager hive to a password-protected archive and, later, by dumping LSASS process memory on multiple machines. The Spirals attackers then used Windows Management Instrumentation (WMI) to move from the initial host to more than a dozen machines within minutes, leveraging accounts assessed as likely or built-in domain administrators. The automated cadence, consistent with scripted tooling, and Active Directory enumeration during the foothold phase appear to have produced the target list used for the subsequent mass ransomware deployment.

#4 Mass Deployment via PsExec

The next day, the operator switched to PsExec running as SYSTEM to push a base64-encoded PowerShell payload to domain controllers, file servers, application servers, virtual machines, and workstations. The payload disabled Windows Defender, removed its threat definitions, and stopped 23 backup, database, and virtualization services — including Exchange, Hyper-V, VMware, Veeam, SQL Server, Oracle, and PostgreSQL — to release file handles ahead of encryption.

#5 Encryption and Double-Extortion

The Rust-based Spirals payload was named bitsadmin.exe to masquerade as the legitimate Windows BITS utility, and dropped in domain-replicated locations to reach machines not directly targeted by PsExec. Files were encrypted with per-file AES-128 keys wrapped using an attacker-controlled ECDH P-256 public key, with intermittent encryption applied to files larger than 5 MB for speed. A ransom note threatened to publish stolen data after six days and directed victims to a Tor negotiation portal, confirming the double-extortion model of the Spirals ransomware attack.


Recommendations

01

Monitor PsExec Mass Deployment

Alert on rapid, sequential PsExec executions targeting many remote hosts within short windows, especially when accompanied by base64-encoded PowerShell payloads delivered as SYSTEM, since this is the exact deployment pattern used to distribute the Spirals ransomware payload across the victim environment.

02

Enforce UAC Enforcement and LSA Protection

Configure UAC to its highest enforcement level, enable Credential Guard, and enable LSA protection (RunAsPPL) to defeat both the UAC bypass and the LSASS credential dumping via rundll32.exe with comsvcs.dll observed in this Spirals ransomware intrusion.

03

Restrict SYSVOL and Domain-Replicated Share Write Access

Audit and tightly restrict write permissions to SYSVOL, DFSR replicated shares, and administrative shares on domain controllers, since the Spirals operators placed the ransomware payload in these locations to achieve domain-wide reach beyond hosts directly targeted by PsExec.

04

Isolate and Segment Backup Infrastructure

Place backup, database, and hypervisor management planes on isolated network segments with distinct credentials, and ensure backup services cannot be enumerated or stopped by domain administrator accounts alone, since Spirals halted 23 categories of backup and virtualization services before encryption.

05

Maintain Immutable, Offline Backups

Keep immutable or offline copies of critical data outside the reach of production Active Directory, and validate restore procedures under time pressure, given the under-24-hour intrusion-to-encryption timeline demonstrated in this Spirals ransomware case.


Indicators of Compromise (IOCs)

Type Value
SHA256 0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141
SHA256 4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649
SHA256 7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b
SHA256 83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892
SHA256 84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c81522d
SHA256 862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1
SHA256 b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556
IPv4 185[.]141[.]216[.]194
URL hxxp[:]//185[.]141[.]216[.]194/cd[.]jpg
URL hxxp[:]//185[.]141[.]216[.]194/cd[.]zip
URL hxxps[:]//computer[.]kplus[.]com/cd[.]zip
URL hxxps[:]//beta[.]padmin[.]com/mybenefits/Templates/cd[.]zip
Filename bitsadmin.exe
Filename vbr2116.exe
Filename revsocks.exe
Filename tunn.exe
Filename chrome.exe
Filename tokens.exe
Filename cloudflared-windows-amd64.exe
Filename RECOVERY_SECTION.log
File Path C:\RECOVERY_SECTION.log
File Path CSIDL_PROFILE\public\tunn.exe
File Path CSIDL_WINDOWS\tasks\tunn.exe
File Path CSIDL_WINDOWS\tasks\chrome.exe
File Path CSIDL_DRIVE_FIXED\webprodprojects\wicapfiles\cloudflared-windows-amd64.exe
File Path CSIDL_WINDOWS\bitsadmin.exe
File Path CSIDL_PROFILE\desktop\bitsadmin.exe
File Path CSIDL_WINDOWS\sysvol_dfsr\domain\scripts\bitsadmin.exe
File Path CSIDL_PROFILE\appdata\local\temp\vbr2116.exe

Potential MITRE ATT&CK TTPs

T1190
Initial Access
Exploit Public-Facing Application
T1505.003
Initial Access
T1505: Server Software Component — Web Shell
T1059.001
Execution
T1059: Command and Scripting Interpreter — PowerShell
T1059.003
Execution
T1059: Command and Scripting Interpreter — Windows Command Shell
T1047
Execution
Windows Management Instrumentation
T1569.002
Execution
T1569: System Services — Service Execution
T1136.001
Persistence
T1136: Create Account — Local Account
T1548.002
Privilege Escalation
T1548: Abuse Elevation Control Mechanism — Bypass User Account Control
T1134
Privilege Escalation
Access Token Manipulation
T1562.001
Defense Evasion
T1562: Impair Defenses — Disable or Modify Tools
T1036.005
Defense Evasion
T1036: Masquerading — Match Legitimate Name or Location
T1036.008
Defense Evasion
T1036: Masquerading — Masquerade File Type
T1140
Defense Evasion
Deobfuscate/Decode Files or Information
T1003.002
Credential Access
T1003: OS Credential Dumping — Security Account Manager
T1003.001
Credential Access
T1003: OS Credential Dumping — LSASS Memory
T1087
Discovery
Account Discovery
T1135
Discovery
Network Share Discovery
T1518.001
Discovery
T1518: Software Discovery — Security Software Discovery
T1057
Discovery
Process Discovery
T1021.002
Lateral Movement
T1021: Remote Services — SMB/Windows Admin Shares
T1021.001
Lateral Movement
T1021: Remote Services — Remote Desktop Protocol
T1560.001
Collection
T1560: Archive Collected Data — Archive via Utility
T1572
Command and Control
Protocol Tunneling
T1090.001
Command and Control
T1090: Proxy — Internal Proxy
T1071.001
Command and Control
T1071: Application Layer Protocol — Web Protocols
T1105
Command and Control
Ingress Tool Transfer
T1041
Exfiltration
Exfiltration Over C2 Channel
T1486
Impact
Data Encrypted for Impact
T1489
Impact
Service Stop
T1490
Impact
Inhibit System Recovery
T1657
Impact
Financial Theft

References


What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Book a Demo of HivePro.