Dire Wolf, also known as DireWolf, direwolf, and dire_wolf, is a financially motivated, human-operated ransomware group active since at least April 2025. It operates a Windows ransomware family of the same name and conducts double-extortion attacks, stealing sensitive data before encrypting files and threatening publication on a Tor-hosted leak site unless victims pay. Its leak site listed 100 claimed victims across 32 countries by August 2026. Targeted sectors include professional services, manufacturing, healthcare, technology, financial services, retail, energy, and transportation, with numerous reported victims in the United States and additional targets in Brazil, the United Kingdom, Thailand, and Malaysia. Dire Wolf's encryptor is written in Go and typically packed with UPX. It generates per-file private keys, performs Curve25519 key exchange using an embedded public key, and applies SHA-256 to derive ChaCha20 encryption material. It fully encrypts files smaller than 1 MB and encrypts only the first 1 MB of larger files. Concurrent workers accelerate encryption, while exclusions for selected executable and system-file types reduce damage that could prevent systems from operating. Before encryption, the malware suppresses Windows event logging, clears event logs, deletes Volume Shadow Copies and backups, disables automatic recovery, and terminates services and processes associated with databases, email, virtualization, backup, and security software. It subsequently places victim-specific ransom notes containing negotiation credentials, forces a reboot, and deletes its executable. Initial-access methods and the group's geographic origin are not established, and no specific CVE exploitation has been attributed to the operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Human-operated double-extortion group whose earliest recorded attack was on 17 April 2025. Its leak site listed 100 victims across 32 countries by 19 August 2026, primarily in professional services, manufacturing, healthcare, technology, and financial services. Operators spend days to weeks inside victim environments before encryption. Reported incidents averaged approximately 265 GB of stolen data, with typical ransom demands around USD 500,000. Initial access methods remain uncertain.
Reportedly conducted a ransomware attack against Softruck, a Brazil-based software organization. The reported breach occurred on October 4, 2026, at 14:24 UTC and was discovered at 14:30 UTC. The content provides no technical details or independent verification of the attribution.
DireWolf lists Softruck (softruck.com), a Brazilian organization categorized as Transportation / Travel / Logistics, as a victim discovered on October 4, 2026. The post provides no stolen-data volume, data types, ransom demand, deadline, or evidence substantiating the compromise.
A ransomware group attributed to 43 incidents during August 2026.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.