Ransomware Intelligence

direwolf

Ransomware group profile

57Victims
United StatesSource country
67Impact score

Description

Dire Wolf is a financially motivated ransomware group that emerged in May 2025 and quickly established itself through disruptive attacks across multiple regions. The group operates a dark web leak site and employs a double extortion model, demonstrating a clear emphasis on monetary profit over any political agenda.

Key insights

  • Gains initial access through spear-phishing, exploitation of exposed services, or weak credentials.
  • Employs a double extortion model, exfiltrating data before encryption and threatening to publish it.
  • Ransomware payload is written in Golang and often uses UPX for obfuscation.
  • Uses Curve25519 for key exchange and ChaCha20 for file encryption.
  • Targets include a variety of sectors with reported ransom demands reaching up to $500,000.

Threat Level & Status Breakdown

For direwolf · Based on incidents in selected period

2.3threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality1.8/ 10

Status Breakdown

Claimed100.0%57
First seenJul 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for direwolf in the selected period

57Total attacks
12peak in Jul
7.1avg / month
↓ 8 vs first month
JulAugSepOctNovDecJanJun036912

Intelligence

IOCs, YARA/Sigma rules, and related families for direwolf

  1. 7f877830ebafb0b809b96bac7baf4435e235ab7835f695006ff779e6178c3638
  2. 831c6ffbe6e3b31a3e9aec27c79f7d42717e8c9d
  3. 4a5852e9f9e20b243d8430b229e41b92949e4d69
  4. f7f4e9366737ab6cc064bc2e5f062ae368e16bbefe845c962dd0c4e9ba919697
  5. 27d90611f005db3a25a4211cf8f69fb46097c6c374905d7207b30e87d296e1b3
  6. aa62b3905be9b49551a07bc16eaad2ff
  7. bc6912c853be5907438b4978f6c49e43
View full IOC feed7 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for direwolf

Other

T1486

T1486

T1490

T1490

T1021

T1021

T1562

T1562

T1078

T1078

T1021.001

T1021.001

T1547

T1547

T1059

T1059

T1047

T1047

T1489

T1489

Victims(57)

CompanyDomainCountryIndustryStatusDiscovered
Nueva Pescanova Groupnuevapescanova.comES SpainOther
Claimed
8 days ago
Did Asiadidasia.co.thTH ThailandManufacturing
Claimed
8 days ago
Clínica Vidaclinicavida.comBR BrazilHealthcare
Claimed
8 days ago
Jewelexjewelexgroup.comCY CyprusRetail & E-Commerce
Claimed
8 days ago
Chemsain Konsultant Sdn Bhdchemsain.comMY MalaysiaManufacturing
Claimed
5 months ago
Perdana Petroleum Berhadperdana.myMY MalaysiaEnergy & Utilities
Claimed
5 months ago
Mohammad Omar Bin Haider Holding Groupmobhholding.comAE United Arab EmiratesProfessional Services
Claimed
5 months ago
Bauerfeindbauerfeind.caDE GermanyHealthcare
Claimed
5 months ago
Bina Darulaman Berhadbdb.com.myMY MalaysiaOther
Claimed
6 months ago
Hydrodiseñohydrodiseno.comES SpainManufacturing
Claimed
6 months ago
Varimed Medikalvarimed.com.trTR TurkeyHealthcare
Claimed
6 months ago
Sunzen Biotech Berhadsunzengroup.comMY MalaysiaHealthcare
Claimed
6 months ago
Laurenzano Logisticslaurenzanologistica.com.arUS United StatesTransportation
Claimed
6 months ago
KwikLedgerskwikledgers.comUS United StatesFinancial Services
Claimed
6 months ago
PernelMediapernelmedia.comFR FranceRetail & E-Commerce
Claimed
6 months ago
Adnan Sundra & Lowasl.com.myMY MalaysiaFinancial Services
Claimed
6 months ago
Sanyang Motorsanyang.com.twTW TaiwanManufacturing
Claimed
6 months ago
Guan Chong Berhadgcbcocoa.comMY MalaysiaOther
Claimed
6 months ago
Office of Public Sector Anti-Corruption Commissionpacc.go.thTH ThailandGovernment & Defense
Claimed
6 months ago
Ranger Investigation Guardranger1992.comTH ThailandProfessional Services
Claimed
6 months ago

Page 1 of 3