The Spirals ransomware, a previously unknown Rust-based strain, was used in a rapid attack achieving initial access, data theft, and full network encryption in under 24 hours. It encrypts files using unique AES-128 keys per file, wrapped with an attacker-controlled ECDH public key. The article provides no information on CVSS scores, affected software versions, patches, or specific workarounds.
A previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access to data theft and encrypting the network in less than 24 hours, according to Symantec’s Threat Hunter Team. Spirals encrypts files quickly after gaining a foothold Spirals is written in Rust and encrypts files using a separate AES-128 key per file, each wrapped with an attacker-controlled ECDH … More → The post Spirals ransomware locks down victim systems in under 24 hours appeared first on Help Net Security .