Spirals Ransomware — New Rust-Based Family Breaches Internet-Facing IIS Server, Encrypts Entire Domain Within 24 Hours — Threadlinqs Intelligence
As of 2026-07-18, Spirals Ransomware — New Rust-Based Family Breaches Internet-Facing IIS Server, Encrypts Entire Domain Within 24 Hours is a critical-severity ransomware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1481 · Severity: CRITICAL · Status: ACTIVE · Category: RANSOMWARE
A previously unseen Rust-based ransomware family named Spirals compromised an internet-facing IIS web server at an IT services company in South Asia on June 16, 2026 via an ASP.NET web shell, then
On June 16, 2026 at 22:21 local time, an unidentified threat actor compromised an internet-facing Microsoft IIS web server belonging to an IT services company in South Asia by uploading an ASP.NET web shell, granting remote command execution through the IIS worker process (w3wp.exe). Within minutes the actor staged multiple tunneling and reverse-proxy tools for redundant, encrypted command-and-control channels: a Chisel binary renamed to chrome.exe, a Cloudflare Tunnel client (cloudflared-windows-amd64.exe) providing outbound HTTPS-based C2, a generic tunneling utility (tunn.exe), and a reverse-SOCKS proxy (revsocks.exe) bound to external port 443. A token-impersonation tool (tokens.exe) was used for local privilege escalation alongside a UAC bypass, and the actor enabled RDP and created a local account for persistent access.
At 23:07 the actor began disabling Windows Defender via MpCmdRun.exe (-RemoveDefinitions -All -DisableRealtimeMonitoring $true -DisableIOAVProtection $true) and downloaded additional tooling, staging some payloads with a .jpg extension to disguise their content during transfer. Credential harvesting followed: the SAM registry hive was dumped to a password-protected archive, and LSASS process memory was dumped on multiple hosts using rundll32.exe in combination with comsvcs.dll (the MiniDump export technique). These credentials, combined with compromised domain-administrator accounts, enabled WMI-based lateral movement beginning at 23:33 against more than a dozen machines within minutes.
On June 17 at 14:12 the actor pivoted to mass deployment using PsExec run as SYSTEM (psexec.exe -accepteula -d -s \\<target> powershell -nop -w 1 -enc <base64 payload>), placing the ransomware binary — deployed under decoy filenames bitsadmin.exe and vbr2116.exe to masquerade as a legitimate Windows utility — into the SYSVOL domain scripts directory (sysvol_dfsr\domain\scripts) and a domain-controller network share for enterprise-wide propagation. By 14:44 the deployment cadence accelerated to more than one new target every few seconds, encrypting machines across the environment during a roughly 30-minute mass-push window. Before detonation the payload forcibly stopped 23 backup, database, and virtualization services — including Veeam, VMware, Hyper-V, Acronis, Veritas, Commvault, SQL Server, Oracle, MySQL, PostgreSQL, Exchange, Intuit, SAP, and Lotus Domino — to maximize both encryption impact and recovery difficulty.
The ransomware itself is a full-featured Rust binary implementing defense evasion, encryption, lateral movement, process termination, obfuscation, and privilege-escalation capability. Each file is encrypted with a unique per-file AES-128 key; those keys are wrapped with an attacker-controlled ECDH P-256 public key so only the attacker's matching private key can recover them. Files larger than 5MB are encrypted intermittently in jittered chunks rather than in full, a common ransomware speed optimization that also complicates some entropy-based detection heuristics. A ransom note (C:\RECOVERY_SECTION.log) was dropped instructing the victim to negotiate via a Tor hidden-service portal that explicitly names the operation "Spirals," and threatens publication of exfiltrated data within six days of non-payment — a classic double-extortion model. The overall operation, from initial web-shell access to full domain encryption, took under 24 hours, with the actor's hands-on-keyboard activity spanning roughly three hours of interactive reconnaissance, Active Directory enumeration, and target-list compilation prior to the automated mass-deployment phase. No attribution to a known ransomware group or affiliate program has been established as of this reporting; "Spirals" is treated as a newly identified, previously unseen ransomware family/brand.
Target sectors: information-technology-services
Target regions: South Asia
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, T1190, T1505, T1136, T1219, T1548, T1134, T1685, T1036, T1027, T1070