Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

185.141.216.194

TLP:CLEAR
Active

IPv4 Address

Description

A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
Pattern Type
STIX
Confidence
75%
Valid From
Jul 17, 2026 02:00
Total Sightings
0
Added
Jul 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 185.141.216.194

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.