Date: 07/20/2026
Severity: High
Summary
Researchers uncovered Spirals, a previously unseen Rust-based ransomware that compromised an IT services company in South Asia, progressing from initial access to data theft and network-wide encryption in less than 24 hours. The attackers exploited an internet-facing IIS server, used web shells, credential dumping, UAC bypass, WMI/PsExec lateral movement, and reverse tunnels to establish persistence before deploying the ransomware. Spirals employs a double-extortion model, threatening to leak stolen data in addition to encrypting files, highlighting the increasing speed and sophistication of modern ransomware operations.
Indicators of Compromise (IOC) List
Domain/Urls | https://beta.padmin.com/mybenefits/Templates/cd.zip https://computer.kplus.com/cd.zip http://185.141.216.194/cd.jpg http://185.141.216.194/cd.zip |
IP Address | 185.141.216.194 |
Hash | 0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141
4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649
7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b
83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892
84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d
862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1
b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "http://185.141.216.194/cd.jpg" or url like "http://185.141.216.194/cd.jpg" or siteurl like "http://185.141.216.194/cd.jpg" or domainname like "http://185.141.216.194/cd.zip" or url like "http://185.141.216.194/cd.zip" or siteurl like "http://185.141.216.194/cd.zip" or domainname like "https://computer.kplus.com/cd.zip" or url like "https://computer.kplus.com/cd.zip" or siteurl like "https://computer.kplus.com/cd.zip" or domainname like "https://beta.padmin.com/mybenefits/Templates/cd.zip" or url like "https://beta.padmin.com/mybenefits/Templates/cd.zip" or siteurl like "https://beta.padmin.com/mybenefits/Templates/cd.zip" |
Detection Query 2 : | dstipaddress IN ("185.141.216.194") or srcipaddress IN ("185.141.216.194") |
Detection Query 3 : | sha256hash IN ("84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d","4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649","862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1","83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892","b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556","0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141","7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b")
|
Reference:
https://www.security.com/threat-intelligence/ransomware-spirals-extortion