Dire Wolf is a ransomware group/malware family that emerged in May 2025. The provided content states it operates an onion-based data leak site and uses double-extortion tactics. It is described as a Golang ransomware threat and is referenced as affecting victims across 11 countries. The content also notes victim-leak activity attributed to Dire Wolf, including a claimed posting involving Perdana Petroleum in Malaysia. No additional high-confidence technical details, infection vector specifics, encryption behavior, ransom note characteristics, or indicators of compromise are provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware written in Golang that employs double extortion tactics and file wiping, targeting victims across 11 countries.
Ransomware operation (surfaced May 2025) using double extortion and an onion-based leak site to publish victim data and pressure payment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.