Dire Wolf is a Go-based ransomware family targeting Windows, used by a human-operated cybercriminal group of the same name. Active since at least April 2025, the operation employs double extortion: operators steal sensitive data before encrypting files and threaten publication on a Tor-hosted leak site unless victims pay. Victims span multiple countries and industries, including professional services, manufacturing, healthcare, technology, and financial services. Its initial-access mechanisms have not been established.
Dire Wolf encryptors are typically packed with UPX and use concurrent workers to process files. For each file, the malware generates a random private key, performs a Curve25519 key exchange with an embedded public key, and uses SHA-256 to derive encryption material for ChaCha20. Files smaller than 1 MB are encrypted completely, while only the first 1 MB of larger files is encrypted. Selected executable, system, and disk-image file types are excluded. Startup checks prevent concurrent or repeated encryption runs.
Before encryption, Dire Wolf terminates processes and services associated with databases, mail, virtualization, backups, and security software. It suppresses Windows event logging, clears event logs, deletes Volume Shadow Copies and backups, and disables automatic recovery to impede detection and restoration. After encryption, it places victim-specific ransom notes in affected directories, records completion, schedules a forced reboot, and deletes its executable.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dire Wolf is a Windows ransomware family used by a human-operated group of the same name. The operators steal sensitive data before encrypting files, then threaten to publish that data on a Tor-hosted leak site unless the victim pays.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows ransomware implemented in Go and typically packed with UPX. Its operators steal data before encryption and threaten publication to extort payment. The encryptor derives a unique ChaCha20 key for each file using Curve25519 and SHA-256, fully encrypting files below 1 MB and only the first 1 MB of larger files. It appends the .direwolf extension. Before encryption, it suppresses and clears event logs, deletes shadow copies and backups, disables recovery, and terminates processes and services. After encryption, it drops HowToRecoveryFiles.txt ransom notes, creates a completion marker, forces a reboot, and deletes itself. The article reports 100 claimed victims across 32 countries by August 2026. Initial access methods remain uncertain.
A ransomware family that appeared in 2025, using identity-based access vectors for initial compromise.
Extortion-focused group that conducts data theft and leak-based extortion attacks, often without deploying traditional ransomware encryption.
Ransomware operation referenced as a mid-volume group impacting industrial sectors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.