[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4zdTmtybEPmB7F9R-GLwNI83-cArPrII8TtEnmD8YNM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"7f035c1f-f8a5-434a-803b-ac07ba2d95fd","spirals-ransomware-encrypts-network-in-under-24-hours-via-exposed-iis-server","e130001d-513e-42b8-a118-d4302a4f5942","Spirals Ransomware Encrypts Network in Under 24 Hours via Exposed IIS Server","An exposed, likely unpatched IIS server provided the initial foothold for the Spirals ransomware operator, who completed a full attack chain—privilege escalation, lateral movement across a dozen systems, security tool disablement, and encryption—in less than 24 hours. The speed of this attack underscores how internet-facing services with unmanaged vulnerabilities dramatically compress the window organizations have to detect and respond. The attacker's ability to move laterally so rapidly indicates insufficient network segmentation and weak endpoint controls. This incident is a stark reminder that IT services firms, which often hold keys to multiple client environments, are high-value targets requiring hardened perimeter defenses and rapid detection capabilities.","**Immediate actions:**\n- Audit and remediate all internet-facing services (especially IIS) by applying the latest security patches and disabling unnecessary features or endpoints.\n- Remove or restrict PsExec and other dual-use administrative tools from systems where they are not operationally required.\n- Enable tamper protection on all endpoint security tools to prevent attackers from disabling them.\n\n**Long-term improvements:**\n- Implement strict network segmentation so that a single compromised host cannot directly reach dozens of other systems without crossing a monitored control boundary.\n- Adopt a vulnerability management program with continuous scanning and SLA-driven remediation timelines for internet-facing assets.\n- Apply the principle of least privilege across all administrative accounts to limit the blast radius of any credential compromise.\n\n**Detection measures:**\n- Deploy behavioral EDR and SIEM rules to alert on rapid lateral movement patterns, mass file encryption activity, and security tool termination attempts.\n- Establish 24\u002F7 monitoring with defined escalation playbooks so that sub-24-hour attack chains trigger immediate human response.\n- Conduct regular threat hunting exercises focused on living-off-the-land techniques such as PsExec usage and unusual privilege escalation sequences.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","CIS Control 16: Application Software Security","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 SC-7: Boundary Protection","NIST SP 800-53 IR-4: Incident Handling","NIST CSF DE.CM-1: Network Monitoring","MITRE ATT&CK T1190: Exploit Public-Facing Application","MITRE ATT&CK T1562.001: Impair Defenses – Disable or Modify Tools","MITRE ATT&CK T1570: Lateral Tool Transfer (PsExec)","published","2026-07-16T12:22:09.697302+00:00","2026-07-16T12:22:09.564+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-spirals-ransomware-encrypts-victim-network-in-under-24-hours\u002F","new-spirals-ransomware-encrypts-victim-network-in-under-24-hours-cd161f","New Spirals ransomware encrypts victim network in under 24 hours",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[51],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"e96741f5-df55-47e4-92a2-0356c9b000ac","2026-07-16","afternoon","ThreatNoir Afternoon Brief — July 16","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-16\u002Fthreatnoir-afternoon-brief-2026-07-16.mp3"]