Dire Wolf is a financially motivated ransomware group that emerged in May 2025 and quickly established itself through disruptive attacks across multiple regions. The group operates a dark web leak site and employs a double extortion model, demonstrating a clear emphasis on monetary profit over any political agenda.
Key insights
•Gains initial access through spear-phishing, exploitation of exposed services, or weak credentials.
•Employs a double extortion model, exfiltrating data before encryption and threatening to publish it.
•Ransomware payload is written in Golang and often uses UPX for obfuscation.
•Uses Curve25519 for key exchange and ChaCha20 for file encryption.
•Targets include a variety of sectors with reported ransom demands reaching up to $500,000.