Spirals ransomware breached a South Asian IT services firm and encrypted its network in under 24 hours

A newly identified ransomware actor called Spirals broke into a South Asian IT services company and went from initial access to data theft and encryption in less than a day. Symantec says the attackers entered through an internet-exposed Microsoft IIS server, uploaded an ASP.NET web shell, enabled Remote Desktop, dumped credentials from the SAM and LSASS, moved laterally with Windows Management Instrumentation (WMI) and PsExec, and used revsocks, Chisel, and Cloudflare Tunnel for persistence. The Rust-based ransomware used intermittent encryption to speed up locking files and dropped a ransom note named RECOVERY_SECTION.log.
Why it matters: This is a fast-moving ransomware playbook that can leave defenders very little time to respond once attackers get in. Organizations with exposed IIS servers should urgently review exposure, hunt for the listed tools and indicators, and verify that endpoint protection, backups, and lateral-movement controls are working.

Sources

New Spirals ransomware encrypts victim network in under 24 hours
Bill Toulas 2026.07.16 100% relevant
This article appears to be the first specific report establishing Spirals as a distinct ransomware actor and documenting its initial observed intrusion.
← Back to all stories