A new ransomware actor called Spirals has been observed completing a full corporate intrusion, from initial access to data theft and encryption, in less than 24 hours, according to cybersecurity researchers. The speed of the attacks marks an escalation in ransomware tactics that could make defense significantly more challenging.
The fast encryption timeline leaves organizations with little time to detect and respond to the intrusion before damage is done. Traditional ransomware attacks typically involve days or weeks of reconnaissance and lateral movement before encryption is triggered, but Spirals operators are compressing this timeline dramatically.
Security researchers tracking the group say it uses a combination of initial access vectors, including compromised remote desktop services, phishing campaigns, and exploitation of unpatched vulnerabilities in internet-facing systems. Once inside, the attackers rapidly escalate privileges, move laterally across the network, and deploy the encryption payload within hours.
The compressed attack timeline has significant implications for defensive strategies. Organizations that rely on extended dwell time detection, where security teams have days or weeks to identify and contain an intrusion before it reaches the ransomware stage, may find themselves unprepared for attacks that move this quickly. Automated detection and response capabilities become increasingly critical.
Ransomware continues to evolve as a threat, with attackers constantly refining their tactics to maximize pressure on victims. The emergence of groups like Spirals that operate on accelerated timelines suggests that the ransomware ecosystem remains highly adaptable and that defenders must continuously update their assumptions about attack timelines and response requirements.
This article was adapted from Bleeping Computer. Read the original here.
