Dire Wolf is a human-operated ransomware operation first documented in May 2025 and associated with financially motivated intrusions. The group is known for operating a dedicated leak site and using double extortion, combining data theft with encryption and the threat of public disclosure to pressure victims. Reporting also indicates some Dire Wolf activity has involved leak-based extortion without deployment of a ransomware locker, suggesting operational flexibility across campaigns. Victimology shows broad multinational targeting across North America, Europe, Asia, and Latin America, with repeated impacts in the United States, Spain, Germany, Thailand, Brazil, Cyprus, the Philippines, Malaysia, Italy, India, Japan, Canada, and the United Kingdom. Observed victims span healthcare, financial services, technology, manufacturing, professional services, consumer services, food production, legal services, and public-sector-related entities. Multiple assessments describe a notable focus on Asia, with recurring victim concentrations in Singapore, Thailand, the Philippines, and Taiwan, and some reporting also highlights Italy. Dire Wolf conducts targeted, operator-driven intrusions rather than relying on fully automated spread. Its extortion workflow uses staged deadlines and direct victim negotiation, including one-to-one communications over Tox, with the leak site serving as the public escalation mechanism when negotiations fail. The group has been ranked among the most active ransomware actors in mid-2026 based on leak-site victim volumes. Technical reporting describes a Go-based Windows encryptor, commonly packed, that encrypts local and accessible network resources while applying exclusions intended to preserve basic operating system stability. The malware uses hybrid cryptography based on Curve25519 key exchange and ChaCha20 file encryption, generates per-file session keys, and may partially encrypt large files to accelerate impact. Reported operational safeguards include use of a mutex and host-processing markers to avoid redundant execution. Post-encryption behavior can include ransom-note deployment, self-deletion, and in some cases forced rebooting. Pre-encryption activity may include disruption of backup and recovery mechanisms and suppression of Windows event logging to hinder restoration and forensic reconstruction. Dire Wolf intrusions have also been associated with use of the SmilingKiller EDR killer, a defense-evasion tool observed in both LockBit and Dire Wolf operations and noted for heavy obfuscation. This supports assessment of strong defense-evasion tradecraft in at least some campaigns. Known aliases include direwolf and dire_wolf.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the threat group responsible for a ransomware attack against Swyft Inc.
Conducting a ransomware attack against AliveCor, Inc., a U.S.-based healthcare organization focused on medical devices and artificial intelligence.
Conducting a ransomware attack against Statista GmbH.
Conducting a ransomware attack resulting in a data breach against Quironsalud in the healthcare sector.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.