How the Ransomware Operates
Spirals is an aggressive double-extortion ransomware strain engineered in Rust, designed to execute rapid intrusions from initial compromise to domain-wide encryption in under twenty-four hours. Threat researchers have observed an organized, multi-stage attack lifecycle that systematically dismantles defenses and accelerates data exfiltration.
1. Initial Access and Execution
Intrusions attributed to Spirals frequently start by exploiting internet-facing Microsoft IIS web servers. Adversaries identify exposed file upload vulnerabilities or unpatched application flaws to plant ASP.NET web shells within public web directories. Once execution is established under the IIS worker process (w3wp.exe), the attackers launch interactive shells using command-line interpreters such as cmd.exe or PowerShell.
2. Persistence and Layered Tunnelling
Within minutes of initial access, operators establish redundant persistence and bypass network boundaries using custom and open-source proxy tooling. Observed binaries include:
Cloudflare Tunnels: Executed via cloudflared-windows-amd64.exe to route inbound administrative traffic over encrypted outbound HTTPS sessions.
Chisel Masquerading: Dropped under names like chrome.exe in scheduled task directories to establish reverse SOCKS tunnels.
Custom Tunneling Utilities: Executables such as tunn.exe and revsocks.exe staged in temporary and public user directories.
Rogue Local Accounts: Creating local administrative accounts and enabling Remote Desktop Protocol (RDP) for direct access.
3. Credential Harvesting and Lateral Movement
To navigate the Windows Active Directory domain, the operators execute memory dumps of the Local Security Authority Subsystem Service (LSASS) using built-in system libraries like rundll32.exe comsvcs.dll, #24. They also extract Security Account Manager (SAM) registry hives into encrypted staging archives. Using captured administrative credentials and token impersonation tools (tokens.exe), the attackers move laterally across domain controllers and core database servers via Windows Management Instrumentation (WMI) and PsExec.
4. Defense Evasion and Service Disruption
Before launching the final encryption routine, the threat group deploys heavily obfuscated, Base64-encoded PowerShell scripts under the SYSTEM context. These scripts forcefully terminate endpoint protections and administrative services:
Disabling Microsoft Defender antivirus features and purging virus definition signatures.
Stopping and deleting volume shadow copies (VSS) to prevent point-in-time recovery.
Force-terminating critical virtualization, database, and backup processes including Veeam, VMware, Hyper-V, Microsoft SQL Server, Oracle, PostgreSQL, and Microsoft Exchange.
5. Rust-Based Encryption Engine
The ransomware payload is frequently disguised as bitsadmin.exe or vbr2116.exe and placed into Active Directory distribution shares such as SYSVOL\domain\scripts for automated enterprise deployment. The Rust-based encryptor utilizes AES-128 encryption paired with elliptic-curve Diffie-Hellman (ECDH P-256) public-key wrapping. To maximize execution speed, the payload applies intermittent encryption on files larger than 5 MB, leaving a ransom note titled C:\RECOVERY_SECTION.log across encrypted systems.