Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

    Date: 07/20/2026

    Severity: High

    Summary

    Researchers uncovered Spirals, a previously unseen Rust-based ransomware that compromised an IT services company in South Asia, progressing from initial access to data theft and network-wide encryption in less than 24 hours. The attackers exploited an internet-facing IIS server, used web shells, credential dumping, UAC bypass, WMI/PsExec lateral movement, and reverse tunnels to establish persistence before deploying the ransomware. Spirals employs a double-extortion model, threatening to leak stolen data in addition to encrypting files, highlighting the increasing speed and sophistication of modern ransomware operations.

    Indicators of Compromise (IOC) List   

    Domain/Urls

    https://beta.padmin.com/mybenefits/Templates/cd.zip

    https://computer.kplus.com/cd.zip

    http://185.141.216.194/cd.jpg

    http://185.141.216.194/cd.zip

    IP Address

    185.141.216.194

    Hash

    0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141

    4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649

    7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b

    83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892

    84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d

    862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1

    b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection 

    Detection Query 1 :

    domainname like "http://185.141.216.194/cd.jpg" or url like "http://185.141.216.194/cd.jpg" or siteurl like "http://185.141.216.194/cd.jpg" or domainname like "http://185.141.216.194/cd.zip" or url like "http://185.141.216.194/cd.zip" or siteurl like "http://185.141.216.194/cd.zip" or domainname like "https://computer.kplus.com/cd.zip" or url like "https://computer.kplus.com/cd.zip" or siteurl like "https://computer.kplus.com/cd.zip" or domainname like "https://beta.padmin.com/mybenefits/Templates/cd.zip" or url like "https://beta.padmin.com/mybenefits/Templates/cd.zip" or siteurl like "https://beta.padmin.com/mybenefits/Templates/cd.zip"

    Detection Query 2 :

    dstipaddress IN ("185.141.216.194") or srcipaddress IN ("185.141.216.194")

    Detection Query 3 :

    sha256hash IN ("84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d","4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649","862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1","83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892","b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556","0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141","7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b")

    Reference: 

    https://www.security.com/threat-intelligence/ransomware-spirals-extortion


    Tags

    StealerInternet Information Services (IIS)WebShellCredential HarvestingPsExecInformation TechnologyMalwareExploitRansomwareRust MalwareSouth Asia

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags