New Spirals Ransomware Used in Double-Extortion Attack on South Asian IT Company

Summary
A previously unseen Rust-based ransomware called Spirals was deployed against a South Asian IT company in June 2026 after attackers compromised an internet-facing IIS server. The actor is unknown; the attack involved data-theft threats and file encryption.
Key points
- Attackers gained access through an internet-facing IIS server using an ASP.NET web shell; ransomware deployment began less than 24 hours later.
- They established persistence, disabled security tools, stole credentials from the SAM hive and LSASS memory, and used tunneling tools for covert remote access.
- WMI and PsExec enabled rapid lateral movement and ransomware deployment across domain controllers, servers, virtual machines, and workstations.
- The attackers disabled Windows Defender and stopped services associated with backup, database, and virtualization products before encryption.
- The Rust-based payload encrypted files using per-file AES-128 keys wrapped with an attacker-controlled ECDH P-256 key; large files were encrypted in intermittent chunks.
- The ransom note threatened to publish stolen data after six days, indicating double extortion. The actor remains unknown, and the report has observed Spirals on one victim network.
Article Details
- Attack Vectors
- Initial access through a compromised internet-facing web server and an uploaded ASP.NET web shell; the server compromise method was not disclosed.
- Interactive command execution through the web shell, followed by a UAC bypass, local account creation, and enablement of remote desktop access.
- Credential harvesting from the SAM hive and LSASS process memory, followed by lateral movement using abused accounts.
- Redundant reverse-proxy and tunneling channels maintained external connectivity; additional payloads were downloaded from an external IP and two staging domains.
- Remote deployment as SYSTEM, with additional ransomware copies placed in domain scripts directories and a domain-controller-hosted network share.
- File encryption accompanied by a ransom-note threat to publish stolen data after six days if payment was not made.
- Defensive Notes
- The article directs readers to the Symantec Protection Bulletin for the latest protection updates.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 185[.]141[.]216[.]194 | External attack infrastructure listed as a network IOC; the article describes an external IP used for reverse-SOCKS connectivity and payload delivery. |
| SHA256 | 0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141 | Spirals ransomware deployed as bitsadmin.exe and vbr2116.exe. |
| SHA256 | 4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649 | Revsocks reverse-SOCKS proxy deployed and executed by the attackers as revsocks.exe. |
| SHA256 | 7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b | Attacker-deployed tunneling utility named tunn.exe. |
| SHA256 | 83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892 | File explicitly identified as suspicious in the article's IOC list. |
| SHA256 | 84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d | Attacker-deployed Chisel tunneling tool renamed chrome.exe. |
| SHA256 | 862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1 | Token impersonation tool executed by the attackers as tokens.exe. |
| SHA256 | b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556 | Attacker-deployed Cloudflared binary named cloudflared-windows-amd64.exe. |
| URL | hxxp[:]//185[.]141[.]216[.]194/cd[.]jpg | Payload or tool staging URL listed as a network IOC; attackers disguised some delivered files with .jpg extensions. |
| URL | hxxp[:]//185[.]141[.]216[.]194/cd[.]zip | Payload or tool staging URL on the external attack infrastructure. |
| URL | hxxps[:]//beta[.]padmin[.]com/mybenefits/Templates/cd[.]zip | External payload or tool staging URL listed as a network IOC. |
| URL | hxxps[:]//computer[.]kplus[.]com/cd[.]zip | External payload or tool staging URL listed as a network IOC. |
MITRE ATT&CK
T1003.001 · LSASS MemoryAttackers dumped LSASS process memory on multiple machines using rundll32.exe and comsvcs.dll.T1003.002 · Security Account ManagerAttackers dumped the SAM hive and stored the credential material in a password-protected archive.T1021.002 · SMB/Windows Admin SharesPsExec remote sessions pushed the same PowerShell payload across numerous network machines as SYSTEM.T1027 · Obfuscated Files or InformationThe mass-deployment commands carried an identical base64-encoded PowerShell payload.T1036.005 · Match Legitimate Resource Name or LocationChisel was renamed chrome.exe, the ransomware was named bitsadmin.exe, and a payload-dropping process presented as svchost.exe.T1047 · Windows Management InstrumentationWMI was used for lateral movement toward more than a dozen machines within the first few minutes of the observed activity.T1059.001 · PowerShellAttackers executed PowerShell through the web shell and delivered encoded PowerShell payloads through PsExec.T1059.003 · Windows Command ShellThe web shell spawned cmd.exe commands through the IIS worker process.T1078 · Valid AccountsLateral movement involved multiple abused accounts, including accounts assessed as likely or built-in domain administrators.T1087 · Account DiscoveryThe operator enumerated users during the initial interactive session.T1090 · ProxyThe operator ran revsocks as a reverse-SOCKS proxy connecting to an external IP on port 443.T1105 · Ingress Tool TransferAttackers downloaded payloads and tools from an external IP and two external staging domains.T1135 · Network Share DiscoveryThe operator enumerated network shares during the foothold phase.T1136.001 · Local AccountThe operator created a local account for persistence.T1218.011 · Rundll32Attackers used rundll32.exe with comsvcs.dll to dump LSASS memory.T1486 · Data Encrypted for ImpactSpirals encrypted files with per-file AES-128 keys wrapped using an attacker-controlled ECDH P-256 public key, using intermittent encryption for files larger than 5 MB.T1489 · Service StopThe deployment payload forcibly stopped running services matching backup, database, and virtualization product names before encryption.T1505.003 · Web ShellAttackers uploaded an ASP.NET web shell to the compromised internet-facing IIS server and used it for interactive execution.T1518 · Software DiscoveryThe operator listed installed program directories on the compromised host.T1548.002 · Bypass User Account ControlThe operator performed local privilege escalation using a UAC bypass.T1562.001 · Disable or Modify ToolsAttackers attempted to uninstall endpoint security tools and later disabled Windows Defender monitoring and removed its threat definitions.T1572 · Protocol TunnelingMultiple tunneling utilities maintained redundant outbound channels, and a Cloudflare tunnel exposed local RDP externally.
Malware
Vendors
Products
Acronislist of 23 backup, database, and virtualization products, including: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino. Stopping theseCommvaultdatabase, and virtualization products, including: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino. Stopping these services beforeHyper-Vmatched a broad list of 23 backup, database, and virtualization products, including: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, andIISbeing pushed to machines on the network. They obtained initial access by compromising an internet-facing IIS web server and uploading an ASP.NET web shell. Over a rapid three-hour interactive session, theyIntuitExchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino. Stopping these services before encryption is standard ransomware practice as itLotus DominoVMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino. Stopping these services before encryption is standard ransomware practice as it ensures that openMicrosoft Exchange Serveror descriptions matched a broad list of 23 backup, database, and virtualization products, including: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit,MySQLproducts, including: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino. Stopping these services before encryption is standardOracleproducts, including: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino. Stopping these services before encryption is standardPostgreSQLincluding: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino. Stopping these services before encryption is standard ransomwareSAPHyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino. Stopping these services before encryption is standard ransomware practice as it ensuresSQL Serverand virtualization products, including: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino. Stopping these services before encryption isVeeama broad list of 23 backup, database, and virtualization products, including: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino.Veritas23 backup, database, and virtualization products, including: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and Lotus Domino. Stopping these servicesVMwarematched a broad list of 23 backup, database, and virtualization products, including: Exchange, Hyper-V, VMware, Veeam, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Intuit, SAP, and LotusWindows Defenderacross the environment. The decoded payload performed two actions in sequence. First, it disabled Windows Defender's real-time monitoring and removed its threat definitions:
Tools
Chiselreverse SOCKS proxy tool was dropped and executed in the same locations. The attackers also deployed the Chisel tunneling tool, renamed as chrome.exe to blend in with the Google Chrome browser:Cloudflare Tunnelto an external IP on port 443 and additionally exposed local RDP externally through a renamed Cloudflare tunnel binary. Payloads and tools were delivered from the same external IP and from two external stagingPsExecThe following day, the operator began deploying the ransomware payload across the victim’s network using PsExec running as SYSTEM. The payload was named bitsadmin.exe, likely to masquerade as the legitimate Windowsrevsocksrundll32.exe and comsvcs.dll. For covert command-and-control, the operator ran a reverse-SOCKS proxy (revsocks) to an external IP on port 443 and additionally exposed local RDP externally through a renamedtokens.exethrough the environment’s network controls. Around the same time, a token impersonation tool named tokens.exe was executed from another web project directory, likely to acquire elevated privileges on the host:tunn.exeutilities were deployed to the host in the first 10 minutes of activity. The first, named tunn.exe (SHA256: 7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b), appeared initially under a