Dire Wolf is a ransomware threat actor active by at least 2026 and tracked under the aliases direwolf and dire_wolf. The group has been observed conducting ransomware intrusions accompanied by data-breach activity, indicating that victim data is stolen as part of operations and used in extortion workflows. Reporting on June 2026 ransomware activity placed Dire Wolf among the most active ransomware groups globally, ranking second by observed case volume with 68 cases. Victimology indicates broad, opportunistic targeting across multiple countries and sectors. Confirmed victims span the United States, Australia, Sweden, the United Kingdom, India, Brazil, Germany, Spain, and the Philippines. Observed sectors include health care, financial services, information technology, education, and professional services. Named victim organizations include universities, health-care providers and health-tech firms, fintech and financial software companies, legal-services firms, data and internet-portal businesses, and software or gaming companies. Available evidence supports classifying Dire Wolf primarily as a financially motivated ransomware actor. The group’s operations are associated with ransomware deployment and data-theft incidents rather than espionage or influence activity. High-confidence behavioral evidence from the supplied facts supports ransomware-linked exfiltration and extortion, but does not establish more specific tradecraft such as initial access methods, privilege escalation paths, persistence mechanisms, or leak-site operations beyond general ransomware victim claims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Arizona State University (ASU).
Conducting a ransomware attack against Wishfully Studios.
Conducting a ransomware attack against Mighty Kingdom.
Conducting a ransomware attack against Eva AI Limited.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.