Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
DireWolf (also written 'Dire Wolf') is a ransomware group that emerged in May 2025, running a double-extortion operation backed by a dedicated dark-web leak site. Its encryptor is written in Go and has been observed delivered as a UPX-packed binary using Curve25519 and ChaCha20 for encryption, appending a .direwolf extension. Reported anti-recovery behavior includes deleting backups/shadow copies, disabling logging, and terminating services. Victim communication is handled over Tox (qTox). Analysis of the encryptor showed hardcoded, per-victim negotiation identifiers, indicating targeted rather than indiscriminate deployment. First publicly analyzed in depth by Trustwave SpiderLabs (LevelBlue) in June 2025.
DireWolf surfaced in May 2025, disclosing its first batch of victims (around six) on its darknet leak site on 26 May 2025. Trustwave SpiderLabs obtained and analyzed an early sample via VirusTotal in June 2025, providing the first detailed technical picture: a Go-based, UPX-packed encryptor using Curve25519 + ChaCha20, .direwolf extension, backup deletion, log disabling, and service termination, with double-extortion pressure via a leak site and Tox contact. Early victimology was concentrated in manufacturing and technology, with an Asia-Pacific skew: initial victims spanned roughly 11 countries led by the United States, Thailand, and Taiwan; later tracking (ransomware.live / RansomLook / SOCRadar) showed activity broadening to ~36 countries and well over 100 leak-site claims by 2026, with heavy Asia-Pacific representation (Singapore, Taiwan, Thailand) alongside Australia and parts of Europe (e.g., Italy). Singapore's CSA issued an advisory on ongoing DireWolf activity. The group remained active into 2026. No credible public reporting establishes a code or operator lineage to an earlier ransomware family.
MENA relevance: DireWolf's own leak site (ransomware.live/group/direwolf) lists two UAE-based victims — Mohammad Omar Bin Haider Holding Group and MCT Group of Companies — so the UAE country tag reflects genuine leak-site claims, though neither is independently confirmed as a successful breach. DireWolf is not otherwise a MENA-focused actor; its broader victimology skews to Asia and the West.
+20 more relationships — see the relationships browser.