Ransomware needs a way in. Stolen credentials are the cheapest one.
direwolf Ransomware Group
Ransomware group profile
Description
Dire Wolf is a financially motivated ransomware group that emerged in May 2025 and quickly established itself through disruptive attacks across multiple regions. The group operates a dark web leak site and employs a double extortion model, demonstrating a clear emphasis on monetary profit over any political agenda.
Key insights
- •Gains initial access through spear-phishing, exploitation of exposed services, or weak credentials.
- •Employs a double extortion model, exfiltrating data before encryption and threatening to publish it.
- •Ransomware payload is written in Golang and often uses UPX for obfuscation.
- •Uses Curve25519 for key exchange and ChaCha20 for file encryption.
- •Targets include a variety of sectors with reported ransom demands reaching up to $500,000.
Threat Level & Status Breakdown
For direwolf · Based on incidents in selected period
Recent activity
Monthly attack count for direwolf in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for direwolf
- aa62b3905be9b49551a07bc16eaad2ff
- 27d90611f005db3a25a4211cf8f69fb46097c6c374905d7207b30e87d296e1b3
- 4a5852e9f9e20b243d8430b229e41b92949e4d69
- 7d589f794115171949fa2a7e3b66dcd4
- acd02a4f8b25e9106400e0a3af63a760
- b6fa7a34b57803d2b80f3f484656d34997231597b6c1aa7fc8a386d6474c8afe
- f0a85f105fa178ffa862bd3fdbc6b7ec642dd46189a10e14786c802fac8978e9
- 50b0567a6974721085f4d2baf2b5104e329a6a2e
- 2337edd0fcdb8e1587aff10766ebc16e93df3304
- 333fd9dd9d84b58c4eef84a8d07670dd
- bc6912c853be5907438b4978f6c49e43
- 44da29144b151062bce633e9ce62de85
- f7f4e9366737ab6cc064bc2e5f062ae368e16bbefe845c962dd0c4e9ba919697
- 31fe32bddd2bd4b825e355516d852476
- a482d7e61ba199cbe005a549249894ba
- 3b97927cde6c906f6b6f03797c21efa7
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for direwolf
T1486
T1486
T1490
T1490
T1021
T1021
T1562
T1562
T1078
T1078
T1021.001
T1021.001
T1547
T1547
T1059
T1059
T1047
T1047
T1489
T1489
Victims(82)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| Oportunidados | Brazil | Claimed | about 17 hours ago | |
| PT Intraco Penta Tbk | Indonesia | Claimed | about 17 hours ago | |
| Honeycomb Insurance | United States | Claimed | about 17 hours ago | |
| Red Clínica | Chile | Claimed | 3 days ago | |
| Erdem Hastanesi | Turkey | Claimed | 3 days ago | |
| THQ Nordic | Sweden | Claimed | 3 days ago | |
| Studio Legale ESE | Italy | Claimed | 8 days ago | |
| National Kidney Registry | United States | Claimed | 8 days ago | |
| Studee | United Kingdom | Claimed | 12 days ago | |
| Reviso Cloud Accounting Limited | Denmark | Claimed | 12 days ago | |
| MCT Group | United Arab Emirates | Claimed | 12 days ago | |
| HP Carriers, Inc. | United States | Claimed | 12 days ago | |
| Allstar Industries | United States | Claimed | 12 days ago | |
| Deer Creek-Mackinaw CUSD | United States | Claimed | 12 days ago | |
| iSON XPERIENCES | Mexico | Claimed | 12 days ago | |
| Diaco Global | United States | Claimed | 12 days ago | |
| Authenticate | United States | Claimed | 12 days ago | |
| ProSim Training Solutions | France | Claimed | 12 days ago | |
| The Revel Collective | United States | Claimed | 12 days ago | |
| Aztec Software | Mexico | Claimed | 12 days ago |
Page 1 of 5
Affected countries(41)
Countries where this group has been reported to target or leak victims.