Spirals is a previously unseen Rust-based ransomware family observed in a June 2026 double-extortion intrusion against an IT services company in South Asia. In the documented case, the operators compromised an internet-facing Microsoft IIS server, deployed an ASP.NET web shell, and rapidly progressed through hands-on-keyboard post-compromise activity to enterprise-wide encryption in less than 24 hours. The intrusion included privilege escalation via UAC bypass, credential theft through SAM and LSASS dumping, persistence through local account creation and remote access enablement, and lateral movement using WMI and PsExec. The operators also established covert access channels with tunneling and proxy tooling and disabled or impaired defenses before encryption by turning off Microsoft Defender protections and stopping backup, database, and virtualization services. Spirals encrypts files with a unique AES-128 key per file, with each key protected using an attacker-controlled ECDH P-256 public key, and uses intermittent encryption on larger files to accelerate impact. The operation followed a double-extortion model, combining file encryption with data theft and threats to publish stolen information within days if payment was not made. Attribution to a known threat actor has not been established, and public reporting has so far tied Spirals to a single victim environment, though the operators were assessed as skilled and capable of broader campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
A base64-encoded PowerShell payload went out to machine after machine.
The payload masqueraded as bitsadmin.exe, a real Windows tool... In some cases, the files wore .jpg extensions as a disguise.
Credential theft came next. The attackers dumped the SAM hive into a password-protected archive. Later, they dumped LSASS memory on several machines using living-off-the-land binaries.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A new Rust-based ransomware family used in a double extortion attack. It encrypts files using per-file AES-128 keys wrapped with an attacker-controlled ECDH P-256 public key, uses intermittent encryption for files over 5 MB, and was deployed rapidly after compromise alongside defense evasion, credential theft, lateral movement, and data theft.
A previously unseen Rust-based ransomware that compromises victim networks rapidly, steals data, encrypts files across the network, and uses a double-extortion model by threatening to leak stolen data.
Ransomware payload developed in Rust and used in a double-extortion attack, combining data encryption with threats to leak stolen data. It was deployed across the victim network within 24 hours of the initial compromise.
A previously unseen Rust-based ransomware family used in a targeted attack. It supports defense evasion, automated lateral movement, process termination, privilege escalation, intermittent file encryption, and drops a ransom note threatening data leakage via a Tor negotiation portal.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.