# Spirals Ransomware Hits IT Firm With Swift Network Encryption

*Published July 20, 2026*
*Source: [https://cybersecuritynews.com/new-spirals-ransomware/](https://cybersecuritynews.com/new-spirals-ransomware/)*

## Executive Summary

The Spirals ransomware attacked a South Asian IT firm, encrypting its network within 24 hours using IIS web shell and PsExec. This swift and orchestrated attack highlights the need for robust internet-facing server defenses.

## Article

In June 2026, a new ransomware strain named Spirals targeted an IT services firm in South Asia, achieving full network encryption in under 24 hours. According to Symantec’s Threat Hunter Team, the attack began with the compromise of an internet-facing IIS web server. The attackers installed an ASP.NET web shell, followed by deploying tunneling tools like Chisel and a Cloudflare tunnel client to establish covert communication channels. They also used a token impersonation tool for privilege escalation.

During a focused three-hour session, the attackers bypassed User Account Control, enabled Remote Desktop Protocol, and created a persistent local account. By 23:07, attempts to disable security tools were underway. By leveraging compromised domain administrator credentials, they moved laterally across the network, infecting over a dozen machines.

On June 17, the attackers switched to using PsExec for mass deployment, pushing a PowerShell payload to network targets. This payload disabled Windows Defender and stopped critical services such as Veeam and SQL Server to prepare for encryption. The ransomware disguised itself as a legitimate Windows utility named bitsadmin.exe, ensuring its spread across the network.

The ransomware leaves a ransom note threatening the leak of stolen data if payment is not made within six days. The note directs victims to a Tor portal for negotiation, clearly identifying the threat as Spirals. While only one attack has been observed, the efficiency of Spirals indicates a highly skilled threat actor capable of scaling operations rapidly. Organizations with internet-facing IIS servers must urgently assess and bolster their defenses.
