Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

direwolf Ransomware Group

Ransomware group profile

84Victims
United StatesSource country
78Impact score

Description

Dire Wolf is a financially motivated ransomware group that emerged in May 2025 and quickly established itself through disruptive attacks across multiple regions. The group operates a dark web leak site and employs a double extortion model, demonstrating a clear emphasis on monetary profit over any political agenda.

Key insights

  • Gains initial access through spear-phishing, exploitation of exposed services, or weak credentials.
  • Employs a double extortion model, exfiltrating data before encryption and threatening to publish it.
  • Ransomware payload is written in Golang and often uses UPX for obfuscation.
  • Uses Curve25519 for key exchange and ChaCha20 for file encryption.
  • Targets include a variety of sectors with reported ransom demands reaching up to $500,000.

Threat Level & Status Breakdown

For direwolf · Based on incidents in selected period

4.6threat level
Aggressiveness10/ 10
Lethality0/ 10
Criticality3.7/ 10

Status Breakdown

Claimed100.0%84
First seenSep 2025
Last seenSep 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedSep 1, 2026

Recent activity

Monthly attack count for direwolf in the selected period

84Total attacks
47peak in Aug
10.5avg / month
↑ 1 vs first month
SepOctNovDecJanJunAugSep015304560

Intelligence

IOCs, YARA/Sigma rules, and related families for direwolf

  1. aa62b3905be9b49551a07bc16eaad2ff
  2. 27d90611f005db3a25a4211cf8f69fb46097c6c374905d7207b30e87d296e1b3
  3. 4a5852e9f9e20b243d8430b229e41b92949e4d69
  4. 7d589f794115171949fa2a7e3b66dcd4
  5. acd02a4f8b25e9106400e0a3af63a760
  6. b6fa7a34b57803d2b80f3f484656d34997231597b6c1aa7fc8a386d6474c8afe
  7. f0a85f105fa178ffa862bd3fdbc6b7ec642dd46189a10e14786c802fac8978e9
  8. 50b0567a6974721085f4d2baf2b5104e329a6a2e
  9. 2337edd0fcdb8e1587aff10766ebc16e93df3304
  10. 333fd9dd9d84b58c4eef84a8d07670dd
  11. bc6912c853be5907438b4978f6c49e43
  12. 44da29144b151062bce633e9ce62de85
  13. f7f4e9366737ab6cc064bc2e5f062ae368e16bbefe845c962dd0c4e9ba919697
  14. 31fe32bddd2bd4b825e355516d852476
  15. a482d7e61ba199cbe005a549249894ba
  16. 3b97927cde6c906f6b6f03797c21efa7
View full IOC feed19 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for direwolf

Other

T1486

T1486

T1490

T1490

T1021

T1021

T1562

T1562

T1078

T1078

T1021.001

T1021.001

T1547

T1547

T1059

T1059

T1047

T1047

T1489

T1489

Victims(82)

BrazilFinancial Servicesoportunidados.com.br
Claimed
about 17 hours ago
IndonesiaManufacturingintracopenta.com
Claimed
about 17 hours ago
United StatesOtherhoneycombinsurance.com
Claimed
about 17 hours ago
ChileHealthcareredclinica.cl
Claimed
3 days ago
TurkeyHealthcareerdemhastahanesi.com.tr
Claimed
3 days ago
SwedenTechnologythqnordic.com
Claimed
3 days ago
ItalyProfessional Servicesstudiolegaleese.it
Claimed
8 days ago
United StatesHealthcarekidneyregistry.com
Claimed
8 days ago
United KingdomEducationstudee.com
Claimed
12 days ago
DenmarkFinancial Servicesreviso.com
Claimed
12 days ago
United Arab EmiratesOthermctuae.com
Claimed
12 days ago
United StatesTransportationhpcarriers.com
Claimed
12 days ago
United StatesManufacturingallstarindustries.com
Claimed
12 days ago
United StatesEducationdeemack.org
Claimed
12 days ago
MexicoHospitalityisonxperiences.com
Claimed
12 days ago
United StatesOtherdiacoglobal.com
Claimed
12 days ago
United StatesTechnologyauthenticateis.com
Claimed
12 days ago
FranceTechnologyprosim.aero
Claimed
12 days ago
United StatesOthertherevelcollective.com
Claimed
12 days ago
MexicoTechnologyaztecsoftware.com
Claimed
12 days ago

Page 1 of 5