A New Ransomware Strain Targets an Asian IT Company

A previously undocumented ransomware strain named Spirals has been identified in an attack against an IT company in Asia, according to investigators who traced the threat actors to a dedicated onion site. On that site, the attackers refer to their own malware as Spirals, giving researchers a name to attach to a threat that had otherwise operated under the radar.

The ransom note left on infected systems is direct: pay within six days, or the attackers will publish the stolen data publicly. Victims are pointed to a Tor-based portal to negotiate terms privately. This is a textbook double-extortion setup, where attackers do not just lock up files, they also steal copies of sensitive data before encryption begins, giving them two separate forms of leverage over a victim.

While the initial reporting centers on a single IT company, the tactics on display, a named onion leak site, a hard deadline, and an anonymous negotiation channel, are consistent with how many modern ransomware operations run their extortion business. That makes Spirals worth understanding even for organizations far removed from the sector it has targeted so far.

Inside the Attack Chain: From Breach to Tor-Based Extortion

Double extortion attacks generally follow a predictable sequence. Attackers first gain access to a network, often through phishing, exposed remote access services, or stolen credentials. Once inside, they move laterally to identify valuable data and systems, exfiltrate copies of sensitive files, and only then trigger the encryption payload that locks victims out of their own systems.

What makes Spirals notable is the speed of that final stage. Separate technical analysis has shown that Spirals ransomware can encrypt an entire network in under 24 hours, a pace that outstrips many established ransomware families. That speed compresses the window defenders have to detect and contain an intrusion before encryption locks down critical systems, which is precisely why response time during an active infection matters so much.

Once encryption is complete, the victim is left with the ransom note directing them to the Tor portal. The six-day deadline for publishing stolen data is a pressure tactic designed to force a quick decision rather than allow time for a measured, coordinated response involving legal counsel, incident responders, and law enforcement.

Why Attackers Use Tor for Negotiation, and What It Doesn't Protect

Tor is a natural choice for ransomware operators running negotiation portals and leak sites. The network routes traffic through multiple relays, making it difficult to trace the physical location or identity of the site's operators. For criminal groups running extortion-as-a-business, that anonymity lets them host a public-facing leak site and private negotiation chat without immediately exposing their infrastructure to takedown efforts.

But it is worth being clear about what Tor anonymity does and does not accomplish in these scenarios. It protects the attackers' identity and location, not the victim's data. Once files have been exfiltrated, the presence of a Tor negotiation channel does not change the underlying fact that sensitive information is already outside the victim's control. Paying a ransom through an anonymous channel offers no guarantee that stolen data will actually be deleted rather than sold or leaked later anyway. Anonymity tools serve the attacker's operational security; they do nothing to restore a victim's data or reverse a breach.

Defensive Measures: Backups, Segmentation, and Incident Response

The practical lesson from the Spirals case is not about Tor at all, it is about resilience before an attack ever starts. A few measures consistently make the biggest difference against double-extortion ransomware:

  • Encrypted, offline backups: Backups that are isolated from the production network and cannot be reached or altered by an active intrusion remain one of the most reliable ways to recover without paying a ransom.
  • Network segmentation: Limiting how far an attacker can move laterally after an initial compromise can prevent a single foothold from becoming a network-wide encryption event, particularly important given how quickly strains like Spirals can spread.
  • Rapid detection and response: Given documented encryption timelines of under 24 hours, the gap between initial compromise and full lockdown is narrow. Monitoring for unusual data transfers and privilege escalation gives defenders a better chance of intervening before encryption begins.
  • Incident response planning: Having a pre-established plan, including legal, communications, and technical response roles, prevents organizations from making rushed decisions under the pressure of a six-day countdown.

What This Means For You

Most readers will never interact with a ransomware Tor negotiation portal directly, but the Spirals case is a useful reminder of how these attacks are structured and why speed matters on both sides. If your organization handles sensitive data, whether as an IT provider or any business reliant on digital infrastructure, the exposure to double-extortion ransomware Tor tactics is real regardless of industry. The core defense is not fighting the attackers' use of anonymity tools, it is making sure your own data and systems are resilient enough that neither encryption nor a leak threat gives them meaningful leverage.

Actionable Takeaways

  • Maintain offline, encrypted backups tested regularly for restoration speed, not just existence.
  • Segment networks so a single compromised endpoint cannot cascade into full encryption.
  • Invest in detection tools capable of flagging unusual data exfiltration, not just encryption activity.
  • Build an incident response plan now, so decisions during a ransom deadline are not made in a panic.
  • Review how quickly Spirals can encrypt a network by reading the technical breakdown of its under-24-hour encryption timeline to understand exactly how narrow the response window really is.