Dire Wolf — Ransomware Profile
Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.IntelFusions coverage (1)
- Mexico is suddenly all over the ransomware leak sites 2026-08-22 · Cyber Incidents
Tools & malware
- Dire Wolf Ransomware Ransomware
- Tox Communication Tool
- UPX Packer
Recent claimed victims
- Allstar Industries 2026-08-21
- HP Carriers 2026-08-21
- MCT Group of Companies 2026-08-21
- Reviso Cloud Accounting Limited 2026-08-21
- NorthStar 2026-08-21
- Studee 2026-08-21
- Authenticate Information Systems 2026-08-21
- Diaco Global 2026-08-21
- iSON XPERIENCES 2026-08-21
- Deer Creek-Mackinaw CUSD 2026-08-21
- Aztec Software 2026-08-21
- The Revel Collective 2026-08-21
- ProSim Aviation Research 2026-08-21
- Photon Health, Inc. 2026-08-19
- InfoFlo CRM 2026-08-19
- PayUp 2026-08-19
- Lifesum 2026-08-19
- Eva AI Limited 2026-08-17
- Arizona State University (ASU) 2026-08-17
- Wishfully Studios 2026-08-17
- Mighty Kingdom 2026-08-17
- TOTVS 2026-08-15
- AAM:HOA Management 2026-08-15
- PayrHealth 2026-08-15
- Colla Health 2026-08-15
Vendor research
- Dire Wolf Ransomware (Protection Bulletin) Symantec
- Dire Wolf Strikes: New Ransomware Group Targeting Global Sectors LevelBlue SpiderLabs
- Dire Wolf Ransomware: Threat Combining Data Encryption and Leak Extortion AhnLab ASEC
- Ongoing Dire Wolf Ransomware Campaign (AL-2025-082) Cyber Security Agency of Singapore