Quick Summary
AllegedExecutive Summary
Direwolf listed Arizona State University (ASU) on its dark web portal on August 17, 2026, marking the group’s first claimed target in the US higher education sector. ASU, a major research institution in Tempe, Arizona, serves over 140,000 students across multiple campuses and online programs. This listing was identified via SOCRadar’s Dark Web Monitoring service and remains unverified. The targeting of such a large educational institution suggests an escalation in the threat actor’s operational scope and the potential value of the data involved. In the preceding 60 days, Direwolf claimed 20 other victims, predominantly within the Technology, Healthcare, and Professional Services sectors, with a significant focus on the United States, the United Kingdom, and Brazil. Notable recent US victims include PayrHealth, Colla Health, AAM:HOA Management, and Leafwell. The expansion to include a prominent public research university indicates a potential shift in Direwolf’s targeting strategy, moving towards larger, data-rich entities beyond its typical victim profile.
Technical Analysis
SOCRadar’s stealer-log telemetry identified 25 records associated with asu[.]edu. Six of these records were classified as employee-on-org-systems, specifically targeting ASU’s central authentication infrastructure. This included the CAS login portal, weblogin.asu[.]edu, with seven records featuring @asu[.]edu handles and numeric student IDs, and also internal web applications webapp4.asu[.]edu and webapp5.asu[.]edu. Furthermore, three additional @asu[.]edu usernames were found on third-party SaaS platforms, which is consistent with workstation compromise. The timestamps for these logs span from December 2024 up to August 17, 2026, the same day the leak-site publication occurred, indicating active and ongoing credential harvesting rather than stale data exposure. The primary risk lies in the potential compromise of ASU’s CAS identity system. A valid CAS session can federate access to a wide array of institutional data across various downstream services. To mitigate this, immediate revocation and forced re-authentication for all accounts appearing on weblogin.asu[.]edu and the identified webapp endpoints are crucial. This should be followed by a comprehensive audit of CAS access logs, commencing from the December 2024 baseline period, to identify any unauthorized access or activity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.