Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
Symantec, Thursday, July 16th, 2026
Symantec detailed Spirals, a new Rust-based double-extortion ransomware used against a South Asian IT services firm in June 2026.
Symantec's Threat Hunter Team disclosed a double extortion ransomware campaign against a South Asian IT services company, deploying previously unseen Rust-based malware the team named Spirals.
The attackers gained entry through an internet-facing IIS web server and within 24 hours had established persistent access, uninstalled endpoint security software, dumped the SAM hive and set up covert remote access, using multiple tunneling tools for redundant command-and-control.
On 17 June operators pushed the payload via PsExec to domain controllers, file servers and workstations, encrypting with AES-128 and threatening to leak data within six days. Symantec expects wider campaigns.