Skip to content
Leak site of spirals, captured by ThreatCluster

spirals

Active

5 tracked victims

About

Written by ThreatCluster from 3 stories

spirals is a ransomware group that appears to operate under an extortion-based model, with reporting indicating encryption is the final visible stage in a broader attack that may include data exfiltration and pressure tactics. The group has 1 claimed victim, with Technology the sector most affected and no recorded data on affected countries. A pattern across the reporting shows campaigns that extend beyond encryption to disable protections—backups are targeted, security tools dismantled, and logs erased before or during encryption. For illustration of the broader pattern, the September 18, 2026 report describes EndZone claiming to compromise Accela.com and steal over 50 GB of data from a government software provider.

Sectors: Financial Services, IT Asset Disposition (ITAD) and e-waste management, Logistics · Countries: AE, OM, UG

Recent victims

View all →
VictimSectorCountryDataPostedStatus
seven seas group
sevenseasgroup.com
Maritime servicesAE—Oct 9, 2026published
Armada Credit BureauFinancial ServicesUG—Sep 24, 2026listed
ASYAD GROUP
asyad.com
LogisticsOman61.7 KiBSep 23, 2026published
PITTSRAD
pittsrad.net
Radiology and health imagingUS—Sep 18, 2026listed
ANYTHINGIT
anythingit.com
IT Asset Disposition (ITAD) and e-waste management—Sep 18, 2026listed

Found by ThreatCluster

6 total from our crawl

Listed on this group's leak site and not present in the aggregated feeds.

Armada Credit Bureau Limited
armadacrb.co.ug · credit reporting and analytics
Sep 25, 2026
T-Minus
Sep 21, 2026

All ransomware groups · Dark web intelligence