Emergence of Direwolf Custom Golang Ransomware
Score: 9/10

Emergence of Direwolf Custom Golang Ransomware

Direwolf is an emerging ransomware group using custom Golang-based malware and double-extortion tactics to target global organizations, particularly in the manufacturing and technology sectors.

Executive Summary

Direwolf (also known as Dire Wolf) is a sophisticated ransomware group that emerged in May 2025, operating as a closed group without an affiliate-based Ransomware-as-a-Service (RaaS) model. The group specializes in victim-specific customization, employing tailored Golang-based encryptors that utilize cryptographically sound Curve25519 and ChaCha20 encryption. Since its inception, Direwolf has targeted over 41 organizations across 13 countries, with a significant 60% concentration in the Asia-Pacific region, including Singapore, Taiwan, and Thailand.

The group's methodology involves extensive pre-breach reconnaissance and the exfiltration of large data volumes (averaging 265GB) prior to encryption to facilitate double-extortion. Evidence suggests a strong link between Direwolf's initial access and credentials compromised by infostealers. The group maintains a professional Tor-based leak site and utilizes Tox messenger for negotiations, demanding ransoms up to $500,000 USD. Despite claims of being based in New York, analysts suspect Eastern European or Russian origins based on linguistic patterns.

Key Details

Threat Name

Direwolf Ransomware

Affects

—

Adversary

Direwolf Other Adversaries and Aliases: Dire Wolf

Malware/Tools

Direwolf, Dire Wolf

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance9
Enterprise Relevance10
Clarity & Structure10
Technical Depth8

Sources