New Spirals Ransomware Encrypts Networks in Less Than 24 Hours
The Spirals ransomware, written in Rust, struck a South Asian IT services company in a lightning attack: from initial compromise to complete network encryption, the attackers operated in less than 24 hours. The speed of action and sophisticated techniques indicate a highly skilled group of operators.
Quick Response
- Spirals is a new ransomware written in Rust that encrypts systems in less than 24 hours
- It uses separate AES-128 keys for each file, wrapped with an attacker-controlled ECDH P-256 public key
- The attackers disabled 23 backup, database, and virtualization products before encryption
- The malware was distributed via a PowerShell payload disguised as a legitimate utility
- Symantec shared compromise indicators to allow companies to check their networks
Advanced Encryption and Persistence Techniques
Spirals adopts a sophisticated encryption mechanism: each file is encrypted with a unique AES-128 key, subsequently wrapped with an attacker-controlled ECDH P-256 public key. To optimize encryption speed, files larger than 5 MB are processed in blocks.
Initial Access via Vulnerable IIS Server
The attackers gained initial access by compromising an Internet-exposed IIS web server, uploading an ASP.NET web shell. From this foothold, they executed commands through the IIS worker process to open an interactive session, bypass User Account Control (UAC), enable Remote Desktop Protocol (RDP), and create a local account to maintain persistent access.
Lateral Movement and Credential Dumping
During WMI-based lateral movement activities, the attackers also dumped the LSASS process memory on multiple machines using rundll32.exe and comsvcs.dll. This method allows extracting credentials stored in memory, further expanding their presence in the compromised network.
Evasion and Communication Techniques
To maintain multiple lines of communication with the compromised network, the attackers configured a reverse SOCKS proxy, a renamed copy of the Chisel tunneling tool hidden as chrome.exe, and a Cloudflare Tunnel client. Some of the tools used in the attack were externally hosted with .jpg extensions, likely to evade basic file type filters.
Disabling Security Systems
The PowerShell payload, disguised as bitsadmin.exe to mimic the legitimate Windows utility associated with the Background Intelligent Transfer Service, disabled Windows Defender and stopped services related to 23 backup, database, and virtualization products, including Veeam, VMware, Hyper-V, SQL Server, Oracle, and PostgreSQL. This operation created an ideal environment for unhindered file encryption.
Expanding Threat
Although so far observed only on one victim network, Spirals' capabilities and stealth suggest that the actors behind it are experienced operators, capable of launching wider campaigns in the future. Companies should closely monitor their environments for any related activity and implement appropriate preventive measures.
Compromise Indicators Available
Symantec has shared compromise indicators related to the attack, providing organizations with the tools necessary to check their networks and identify any signs of suspicious activity. This step is crucial to preventing further compromises and mitigating the risks associated with this new type of ransomware.
Impact on the Cybersecurity Market
The emergence of Spirals represents another piece in the increasingly complex ransomware landscape. According to Cybersecurity Ventures data, ransomware attacks will cost businesses globally $265 billion by 2031, with a 30% annual increase. Spirals fits into this trend, demonstrating how cybercriminals are investing in the development of more sophisticated and faster malware.
Comparison with Other Modern Ransomware
Compared to other recent ransomware like LockBit 3.0 and BlackCat, Spirals stands out for its execution speed and use of Rust, a programming language less common in this context. For example, LockBit 3.0 uses a more traditional C++-based approach, while BlackCat is written in Rust but has a longer encryption time. Spirals' ability to encrypt a network in less than 24 hours makes it particularly dangerous, especially for small and medium-sized businesses that may not have the resources to respond quickly to an attack of this magnitude.
Implications for Businesses
For businesses, the advent of Spirals underscores the importance of adopting a multi-layered defense strategy. This includes not only technical solutions such as advanced firewalls and intrusion detection systems, but also robust security practices such as network segmentation, multi-factor authentication, and continuous staff training. In particular, Spirals' ability to disable backup systems requires a more resilient approach to backup management, such as using offline or cloud backups not connected to the main network.
The Role of Training and Awareness
Staff training is another critical aspect. Ransomware attacks often exploit human weaknesses, such as lack of awareness of the dangers of email attachments or downloads from unverified sources. Companies should invest in regular training programs to raise employee awareness of risks and best practices to prevent attacks. This includes understanding the warning signs of an impending attack and the procedures to follow in case of suspected compromise.
Preparation and Incident Response
Another fundamental aspect is preparation for incident response. Companies should have a detailed plan to respond to a ransomware attack, including steps to isolate compromised systems, restore backups, and communicate with stakeholders. This plan should be regularly tested through simulation exercises to ensure that all team members know what to do in case of an attack. Additionally, companies should consider purchasing specific cyber risk insurance coverage, which can help mitigate financial losses in case of an attack.
Collaboration and Information Sharing
Collaboration between businesses and sharing information about ransomware attacks are equally important. Initiatives like the No More Ransom Project, which provides tools for data recovery and information about attacks, can help improve overall resilience against ransomware. Companies should actively participate in these initiatives and share their experiences to help other organizations protect themselves from similar attacks.
Future Perspectives
Looking ahead, it is likely that ransomware like Spirals will become even more sophisticated and difficult to detect. Threat actors will continue to invest in the development of new tools and techniques to evade business defenses. However, with a combination of advanced technologies, robust security practices, and a strong culture of awareness, companies can significantly improve their ability to resist these attacks and protect their data and systems.
The Spirals attack serves as a warning to all organizations about the need to remain vigilant and proactive in their defense against ransomware. As cybercriminals continue to develop new methods to evade defenses, businesses must adopt an integrated approach that combines advanced technologies, robust security practices, and a strong culture of awareness. Only through these combined efforts will it be possible to effectively address the growing threat of ransomware and protect the critical data and systems of organizations.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.