Spirals is a newly identified ransomware actor and associated ransomware family first observed in June 2026. It has been linked to a rapid enterprise intrusion in which the operators progressed from initial access to lateral movement, data theft, and ransomware deployment in less than 24 hours. Observed activity indicates a fast-moving, hands-on-keyboard intrusion model centered on abusing exposed Microsoft IIS infrastructure, establishing persistence through legitimate accounts and web shell access, and then using built-in administrative mechanisms to expand control across the victim environment. Documented Spirals tradecraft includes exploitation of a public-facing IIS server for initial access, persistence via local or valid accounts, reconnaissance of Active Directory and critical enterprise assets, privilege escalation to administrative levels, credential theft through SAM and LSASS dumping, lateral movement using remote administration channels such as WMI, PsExec, SMB, RDP, and Remote PowerShell, and exfiltration of sensitive data prior to encryption. The actor has also been observed enabling remote access, creating redundant access paths through tunneling utilities, disabling Microsoft Defender, attempting to remove security software, and stopping backup, database, and virtualization services before launching encryption. This combination of valid-account abuse, administrative tool use, and defense evasion is consistent with modern big-game ransomware operations designed to compress dwell time and complicate detection. The Spirals malware itself has been described as Rust-based and uses AES-128 with attacker-controlled ECDH P-256 key protection. It employs intermittent encryption for larger files to accelerate impact at scale. The actor has threatened victims with public release of stolen data if payment is not made, indicating a double-extortion model that combines file encryption with data-theft pressure. At present, public reporting ties Spirals to a very limited number of observed incidents, including an intrusion against an IT services firm in South Asia. It remains unclear whether Spirals represents an emerging broader ransomware operation or a custom payload used for a specific intrusion set. Based on observed behavior, Spirals should be regarded as a financially motivated ransomware threat actor with strong capabilities in rapid post-compromise expansion, credential theft, lateral movement, defense evasion, exfiltration, and enterprise-wide encryption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly identified ransomware operation characterized by extremely rapid intrusion-to-encryption timelines, including compromise, lateral movement, data exfiltration, and ransomware deployment in under 24 hours using a double extortion model.
Conducted a rapid ransomware intrusion against an IT services firm in South Asia, moving from IIS server compromise to data theft and encryption in under 24 hours, using double-extortion tactics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.