Threat Group Profile
direwolf
● Active — last 30 days
Victim claims
40
First seen
Jun 2026
Last activity
21 Aug 2026
Tracked since
May 2025
Group overview
Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.
Preferred targets
Healthcare · 9
Technology · 9
Financial Services · 5
Other · 3
Professional Services · 3
Education · 3
Most targeted countries
US · 16
ES · 2
BR · 2
MX · 2
SE · 2
CA · 1