The bottom line: A new ransomware group named Spirals executes enterprise attacks in less than 24 hours — an unusually aggressive pace that puts existing defense processes under pressure.
The newly emerged ransomware group Spirals carries out enterprise attacks from network access to data exfiltration and encryption in under 24 hours. This extreme speed significantly reduces the reaction window for security teams.
Spirals is a new ransomware group that emerged in 2024 and is characterized by an unusually high attack speed. After gaining initial access to systems, the group completes the entire attack cycle — data exfiltration, lateral movement, and full network encryption — in less than 24 hours. This differs significantly from other established ransomware actors, who typically require multiple days for reconnaissance and preparation.
The rapid operational approach presents significant challenges for CISOs in detection and defense. An attack window of under 24 hours means that conventional monitoring and response processes may be insufficient to block the malware before critical systems are encrypted. Automated security mechanisms and real-time threat detection become the deciding factors.
Organizations should review their incident response playbooks and work specifically towards shortening their own reaction time window. Network segmentation, isolation of critical systems, and continuous logging are central to slowing attacks of this kind and preventing attackers from spreading unchecked.
Source: www.bleepingcomputer.com · Published 16 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.