Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

direwolf Ransomware Group

Ransomware group profile

98Victims
United StatesSource country
80Impact score

Description

Dire Wolf is a financially motivated ransomware group that emerged in May 2025 and quickly established itself through disruptive attacks across multiple regions. The group operates a dark web leak site and employs a double extortion model, demonstrating a clear emphasis on monetary profit over any political agenda.

Key insights

  • •Gains initial access through spear-phishing, exploitation of exposed services, or weak credentials.
  • •Employs a double extortion model, exfiltrating data before encryption and threatening to publish it.
  • •Ransomware payload is written in Golang and often uses UPX for obfuscation.
  • •Uses Curve25519 for key exchange and ChaCha20 for file encryption.
  • •Targets include a variety of sectors with reported ransom demands reaching up to $500,000.

Threat Level & Status Breakdown

For direwolf · Based on incidents in selected period

3threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality4.2/ 10

Status Breakdown

Claimed100.0%98
First seenOct 2025
Last seenSep 2026
Avg ransom—
Payment rate—
Statusactive
Sophistication0
Last updatedSep 24, 2026

Recent activity

Monthly attack count for direwolf in the selected period

98Total attacks
47peak in Aug
14avg / month
↑ 16 vs first month
OctNovDecJanJunAugSep015304560

Intelligence

IOCs, YARA/Sigma rules, and related families for direwolf

  1. aa62b3905be9b49551a07bc16eaad2ff
  2. 27d90611f005db3a25a4211cf8f69fb46097c6c374905d7207b30e87d296e1b3
  3. 4a5852e9f9e20b243d8430b229e41b92949e4d69
  4. 7d589f794115171949fa2a7e3b66dcd4
  5. acd02a4f8b25e9106400e0a3af63a760
  6. b6fa7a34b57803d2b80f3f484656d34997231597b6c1aa7fc8a386d6474c8afe
  7. f0a85f105fa178ffa862bd3fdbc6b7ec642dd46189a10e14786c802fac8978e9
  8. 50b0567a6974721085f4d2baf2b5104e329a6a2e
  9. 2337edd0fcdb8e1587aff10766ebc16e93df3304
  10. 333fd9dd9d84b58c4eef84a8d07670dd
  11. bc6912c853be5907438b4978f6c49e43
  12. 44da29144b151062bce633e9ce62de85
  13. 31fe32bddd2bd4b825e355516d852476
  14. a482d7e61ba199cbe005a549249894ba
  15. 3b97927cde6c906f6b6f03797c21efa7
View full IOC feed18 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for direwolf

Other

T1486

T1486

T1490

T1490

T1021

T1021

T1562

T1562

T1078

T1078

T1021.001

T1021.001

T1547

T1547

T1059

T1059

T1047

T1047

T1489

T1489

Victims(96)

Government & Defense
Claimed
10 days ago
Healthcare
Claimed
10 days ago
MalaysiaTransportationptp.com.my
Claimed
14 days ago
United KingdomFinancial Servicesrelycomply.com
Claimed
16 days ago
United StatesProfessional Servicessalesboomerang.com
Claimed
16 days ago
United StatesHealthcareems1r.com
Claimed
17 days ago
United StatesTransportationprecisionvehiclelogistics.com
Claimed
17 days ago
ColombiaEducationtrainme.co
Claimed
18 days ago
United StatesProfessional Serviceslightcast.io
Claimed
18 days ago
SwedenManufacturingsemperlaser.com
Claimed
18 days ago
United StatesHealthcaredentalbilling.com
Claimed
19 days ago
United StatesHealthcaremylaurelhealth.com
Claimed
19 days ago
United StatesHealthcaremissionpethealth.com
Claimed
19 days ago
United StatesTechnologywolfram.com
Claimed
20 days ago
South AfricaTransportationcartrack.co.za
Claimed
22 days ago
ThailandEnergy & Utilitiespttor.com
Claimed
23 days ago
BrazilFinancial Servicesoportunidados.com.br
Claimed
24 days ago
IndonesiaManufacturingintracopenta.com
Claimed
24 days ago
United StatesOtherhoneycombinsurance.com
Claimed
24 days ago
ChileHealthcareredclinica.cl
Claimed
26 days ago

Page 1 of 5