Dire Wolf is a ransomware threat group associated with victim claims against organizations in multiple countries, particularly the United States. Reported targets include organizations in healthcare, transportation and logistics, financial services and insurance, technology and software, industrial machinery, and maritime transportation. Additional reported victims are located in Malaysia, the United Kingdom, South Africa, Indonesia, Brazil, Chile, Turkey, and Sweden. The group appeared among the more active ransomware claimants during several 2026 weekly reporting periods, including 21 claims in one week and eight claims in another. Available reporting does not establish the group’s geographic origin, malware implementation, access vectors, use of data theft, encryption behavior, extortion model, or operational relationship to other ransomware groups. Reported victim listings should be treated as unverified criminal claims absent independent confirmation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware/extortion group claiming eight compromises during week 37 of 2026.
Conducted a ransomware attack against Port of Tanjung Pelepas, a Malaysian marine shipping and transportation organization.
Conducted a ransomware attack against RelyComply AML Platform, a UK financial-services software organization.
Conducted a ransomware attack against Sales Boomerang, a US-based provider of accounting/finance software, analytics and performance software, and customer relationship management services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.