ShellCodeX
Tools • Events • News • Insights
SEO Checker
Threat Group Profile

direwolf

● Active — last 30 days
Victim claims 40
First seen Jun 2026
Last activity 21 Aug 2026
Tracked since May 2025

Group overview

Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.

Preferred targets

Healthcare · 9 Technology · 9 Financial Services · 5 Other · 3 Professional Services · 3 Education · 3

Most targeted countries

US · 16 ES · 2 BR · 2 MX · 2 SE · 2 CA · 1

Victim Claims Timeline

Back to radar
🇺🇸 United States

AliveCor, Inc.

alivecor.com

medical device and artificial intelligence

Healthcare
🇩🇪 Germany

Statista GmbH

statista.com

Data Collection & Internet Portals

Professional Services
🇪🇸 Spain

Quironsalud

quironsalud.com

Hospitals & Physicians Clinics

Healthcare
🇵🇭 Philippines

Health Carousel

healthcarousel.com

Business Services · Ohio

Healthcare
Unknown

Fondo

fondo.com

Financial Software

Financial Services
🇺🇸 United States

Osmo Wallet

osmomoney.com

FinTech

Financial Services
🇨🇾 Cyprus

Jewelex

jewelexgroup.com

Manufacturing

Consumer Services
🇧🇷 Brazil

Clínica Vida

clinicavida.com

Healthcare Services

Healthcare
🇹🇭 Thailand

Did Asia

didasia.co.th

Automotive Parts

🇪🇸 Spain

Nueva Pescanova Group

nuevapescanova.com

Food & Beverage

Agriculture and Food Production