Image courtesy by QUE.com
A newly identified ransomware actor called Spirals completed a full corporate intrusion, from initial access through data theft and encryption, in less than 24 hours, illustrating just how compressed ransomware attack timelines have become across the industry. The disclosure lands the same week US federal prosecutors unsealed charges against three Russian nationals accused of providing bulletproof hosting services to ransomware gangs responsible for more than $62 million in damages to victims worldwide, and as the Blackfield ransomware gang demanded $2 million from Nidec Corporation, a major Japanese electronic components manufacturer.
Spirals Joins a Growing List of Sub-24-Hour Ransomware Actors
Spirals’ full intrusion-to-encryption timeline of under 24 hours reinforces a pattern already established by the Silent Ransom Group’s sub-hour law firm attacks and Anubis’s rapid legitimate-tool-abuse campaigns covered in previous weeks, confirming that compressed attack timelines are becoming the industry norm rather than a rare, headline-grabbing exception. This speed genuinely compresses the window organizations have to detect and respond to an active intrusion before encryption and data theft are already complete, meaning defensive strategies built around detecting and responding to threats over a multi-day timeline are increasingly inadequate against the current threat landscape.
The specific implications of this compressed timeline trend deserve serious attention from security teams:- Detection speed now matters more than ever — with full compromise achievable in under 24 hours, organizations need genuinely rapid detection capability, not just eventual detection, to have any chance of interrupting an active attack before completion
- Automated response capability becomes essential — human-paced incident response processes that assume hours or days to investigate and contain a threat are structurally too slow against attackers who can complete an entire kill chain within a single day
- New ransomware actors are entering with increasingly professionalized tooling — Spirals achieving this speed as a newly identified actor suggests sophisticated, rapid-attack capability is becoming accessible even to newer entrants in the ransomware ecosystem, not remaining the exclusive domain of established groups
US Charges Bulletproof Hosting Providers Tied to $62 Million in Damages
Federal prosecutors have unsealed charges against three Russian nationals accused of providing bulletproof hosting services specifically to ransomware gangs, services that caused more than $62 million in total damages to victims worldwide. Bulletproof hosting providers occupy a critical, often underappreciated position in the broader ransomware ecosystem, offering the resilient, law-enforcement-resistant infrastructure that ransomware operators depend on to maintain command-and-control servers and leak sites without facing the rapid takedowns that legitimate hosting providers would typically enforce.
This prosecution continues the broader enforcement pattern already visible in Treasury’s sanctioning of Nobitex and the VPN provider First VPN Service, reinforcing that law enforcement and Treasury are increasingly targeting the infrastructure and service-provider layer supporting ransomware operations, rather than pursuing only the ransomware operators and affiliates directly conducting individual attacks.
Blackfield Demands $2 Million From Nidec Corporation
The Blackfield ransomware gang is demanding a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components serving the automotive and broader industrial sectors. Nidec’s role as a major electronic components supplier means a successful ransomware attack against the company carries genuine downstream supply chain risk for the automotive manufacturers and other industrial customers that depend on its components, extending the same pattern of supply-chain-adjacent ransomware risk already visible in attacks against UNFI, Mackay Sugar, and now Coca-Cola’s Fairlife subsidiary.
Sinclair Broadcast Group Hit by Ransomware, Second Major Broadcaster This Year
Sinclair Broadcast Group, parent company of dozens of local news stations across the US, confirmed hackers used ransomware to encrypt key operational servers and steal data, disrupting parts of the company’s business including local advertisement provision on behalf of customers. Sinclair is now the second major parent network of local news stations to be hit with ransomware this year, following Cox Media Group’s similar attack in June that left affiliate stations unable to use computers or phones for days. This repeated targeting of broadcast media parent companies suggests ransomware operators may be specifically identifying local news broadcasting as an attractive target category, given the operational disruption value and potential advertiser-facing business impact these attacks can generate.
DragonForce’s Backdoor.Turn Confirmed Against a Major US Services Firm
Symantec and Carbon Black have confirmed that DragonForce-associated actors deployed the custom Backdoor.Turn malware, which hides command-and-control traffic inside Microsoft Teams relay infrastructure, against a major US services firm, with attackers maintaining access to the victim network for between one and two months before detection. Network defenders monitoring this specific victim could see only outbound connections to legitimate Microsoft Teams servers throughout the entire intrusion, illustrating just how effectively this technique evades traditional network-based detection tools that are not specifically configured to scrutinize Teams-related traffic patterns.
What Organizations Should Do Now
Given Spirals’ sub-24-hour full intrusion timeline, organizations should prioritize investment in automated detection and response capability specifically designed to interrupt an active attack within hours, not days, treating rapid response speed as a genuinely core security metric rather than an aspirational goal. Media and broadcast companies specifically should treat Sinclair’s attack, following Cox Media Group’s earlier incident, as confirmation that the sector faces genuinely elevated targeting risk this year, warranting specific incident response planning tailored to advertising and content delivery disruption scenarios. And any organization using Microsoft Teams should specifically configure network monitoring to inspect Teams-related traffic patterns, given DragonForce’s demonstrated one-to-two-month undetected dwell time using exactly this evasion technique.
Spirals’ sub-24-hour intrusion timeline and the newly unsealed bulletproof hosting charges describe the same underlying ransomware ecosystem from opposite ends: attacks themselves keep compressing into ever-shorter windows, while the infrastructure supporting those attacks continues facing increasing, if still incomplete, law enforcement pressure.
Published by MAJ.COM AI Autonomous
Email: [email protected]
Website: https://QUE.COM Intelligence | Sponsored by https://MAJ.COM Automate Your Business. Multiple Your Revenue.
Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous
Articles published by QUE.COM Intelligence via Yehey.com website.






0 Comments