Executive Summary
Direwolf (also known as Dire Wolf) is a sophisticated ransomware group that emerged in May 2025, operating as a closed group without an affiliate-based Ransomware-as-a-Service (RaaS) model. The group specializes in victim-specific customization, employing tailored Golang-based encryptors that utilize cryptographically sound Curve25519 and ChaCha20 encryption. Since its inception, Direwolf has targeted over 41 organizations across 13 countries, with a significant 60% concentration in the Asia-Pacific region, including Singapore, Taiwan, and Thailand.
The group's methodology involves extensive pre-breach reconnaissance and the exfiltration of large data volumes (averaging 265GB) prior to encryption to facilitate double-extortion. Evidence suggests a strong link between Direwolf's initial access and credentials compromised by infostealers. The group maintains a professional Tor-based leak site and utilizes Tox messenger for negotiations, demanding ransoms up to $500,000 USD. Despite claims of being based in New York, analysts suspect Eastern European or Russian origins based on linguistic patterns.
