Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour Encryption — Threadlinqs Intelligence
As of 2026-07-17, Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour Encryption is a high-severity ransomware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1448 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
A previously unseen Rust-based ransomware family named Spirals compromised an internet-facing IIS web server at a South Asian IT services company, deploying an ASP.NET web shell for initial access,
In mid-June 2026, Symantec's Threat Hunter Team observed a double-extortion ransomware intrusion against an IT services company in South Asia carried out by operators using a newly identified, full-featured Rust ransomware family they named 'Spirals'. The attackers gained initial access by compromising a publicly exposed Microsoft IIS web server and uploading an ASP.NET web shell, which they used to spawn cmd.exe and powershell.exe through the IIS worker process (w3wp.exe).
Over a rapid, roughly three-hour interactive session beginning 2026-06-16 22:21 local time, the operators bypassed User Account Control, enabled Remote Desktop Protocol, created a local persistence account, enumerated users/shares/installed software, and dumped the SAM hive to a password-protected archive. Within the first ten minutes of access they staged a suite of redundant tunneling and remote-access tools directly in the IIS web production directory and the Windows Tasks folder: a generic tunneling binary (tunn.exe), a reverse SOCKS proxy (revsocks.exe), the Chisel tunneling tool renamed chrome.exe to blend in with the legitimate Google Chrome browser, the official Cloudflare Tunnel client (cloudflared-windows-amd64.exe) used to expose internal RDP externally, and a token-impersonation utility (tokens.exe). All channels rode outbound port 443 to blend with normal HTTPS traffic. Staged payloads were fetched from an attacker-controlled IP over HTTP using a .jpg file extension to evade content filtering, and were also observed hosted on what appear to be compromised third-party web servers.
Beginning at 23:33 the same night, the operators pivoted to WMI-based lateral movement targeting domain administrator accounts, dumping LSASS process memory via 'rundll32.exe comsvcs.dll MiniDump', and reaching more than a dozen additional hosts within minutes. Ransomware precursor activity was already visible by 23:07, less than 90 minutes after initial access.
On 2026-06-17 at approximately 14:12, the operators used PsExec (running as SYSTEM) to push a base64-encoded PowerShell defense-evasion payload to an extensive target list of domain controllers, file servers, application servers, virtual machines, and workstations, likely derived from prior Active Directory enumeration — one source host fired off new PsExec pushes to fresh targets every few seconds for roughly 30 minutes. The PowerShell payload disabled Windows Defender real-time monitoring and IOAV protection via MpCmdRun.exe, removed AV threat definitions, and forcibly stopped services associated with 23 backup, database, and virtualization products including Veeam, VMware, Hyper-V, SQL Server, Oracle, MySQL, PostgreSQL, Acronis, Veritas, Commvault, Exchange, Intuit, SAP, and Lotus Domino.
By 14:44 on 2026-06-17 — under 24 hours after the initial web shell upload — the Spirals ransomware payload itself, masquerading under the filename bitsadmin.exe (and also observed as vbr2116.exe), was pushed network-wide via the same PsExec mechanism. Spirals is a full-featured Rust binary supporting defense evasion, encryption, lateral movement, process termination, obfuscation, and privilege escalation. It encrypts files using per-file AES-128 keys, each wrapped with an attacker-controlled ECDH P-256 public key; files larger than 5 MB are encrypted intermittently in jittered chunks to speed up mass encryption. A ransom note, RECOVERY_SECTION.log, is dropped at the root of C:\, directing victims to a Tor negotiation portal and threatening publication of exfiltrated data within six days if no ransom is paid — a classic double-extortion model.
Symantec did not attribute the intrusion to a named, previously tracked threat actor or ransomware-as-a-service brand, but assessed that the operators' speed, tooling discipline (redundant C2 channels, living-off-the-land binary masquerading, systematic AD-driven targeting), and operational tempo indicate skilled operators capable of running broader campaigns despite only a singl
Weaknesses (CWE)
CWE-434, CWE-306, CWE-522, CWE-798
Target sectors: information technology, managed service providers
Target regions: South Asia, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1592, T1190, T1505.004, T1136.001, T1021.001, T1548.002, T1078.002, T1562.001, T1070, T1027.001