
New Rust-based Spirals Ransomware Executes Full Attack in Under 24 Hours on South Asian IT Firm
NewscybercrimeransomwareSymantecRustmalwareAES-128ECDHSouth Asia
A previously unknown ransomware strain named Spirals was deployed in an attack against an IT services company in South Asia last month, with threat actors achieving initial access, data theft, and full network encryption in under 24 hours. The malware, written in Rust, employs AES-128 encryption per file, each key secured with an attacker-controlled ECDH mechanism. Symantec’s Threat Hunter Team identified the campaign, noting the ransomware’s rapid execution after gaining a foothold. No specific victim organization, CVE identifiers, or ransom demands were disclosed in the report.