« All threats

Ransomware group

Direwolf

Dire Wolf is a recently emerged double-extortion ransomware group that first appeared around May 2025. It is a crypto-ransomware and data broker targeting industries like manufacturing and technology across multiple countries, including the U.S., Thailand, Taiwan, Singapore, Türkiye, among others. Written in Go and delivered as a UPX-packed binary, it utilizes robust encryption (Curve25519 and ChaCha20) to lock files with a .direwolf extension, while deleting backups, disabling logging, and terminating key services to block recovery. Victims receive highly customized ransom notes containing live-chat credentials and victim-specific portals, indicating a highly professional and targeted approach.

Victims in the last 90 days62

Most affected countries

  1. United States8
  2. Chile1
  3. Germany1
  4. Spain1
  5. United Kingdom1
  6. Brazil1
  7. Italy1
  8. Malaysia1

Most affected sectors

  1. Other19
  2. Technology16
  3. Healthcare12
  4. Transport & logistics3
  5. Media & entertainment2
  6. Finance & insurance2
  7. Legal2
  8. Education2

Recent victims

OrganisationCountrySectorClaimedStatus
🔒 Entidad sin clasificar—Other9/14/2026◌ Claimed (unverified)
Hazel Health—Healthcare9/14/2026◌ Claimed (unverified)
Port of Tanjung PelepasMalaysiaTransport & logistics9/11/2026◌ Claimed (unverified)
RelyComply AML Platform—Technology9/9/2026◌ Claimed (unverified)
🔒 Entidad comercial—Other9/9/2026◌ Claimed (unverified)
🔒 Entidad sin clasificación clara—Other9/8/2026◌ Claimed (unverified)
🔒 Entidad de sector no determinado—Other9/7/2026◌ Claimed (unverified)
Precision Vehicle Logistics—Transport & logistics9/7/2026◌ Claimed (unverified)
Lightcast—Other9/7/2026◌ Claimed (unverified)
🔒 Entidad sin información suficiente—Other9/7/2026◌ Claimed (unverified)
eAssist Dental Solutions—Healthcare9/6/2026◌ Claimed (unverified)
Mission Pet Health—Healthcare9/6/2026◌ Claimed (unverified)
myLaurel—Other9/6/2026◌ Claimed (unverified)
Wolfram ResearchUnited StatesTechnology9/4/2026◌ Claimed (unverified)
Cartrack Holdings—Technology9/2/2026◌ Claimed (unverified)
PTT Oil and Retail Business—Energy & utilities9/2/2026◌ Claimed (unverified)
Honeycomb Programs Inc—Technology9/1/2026◌ Claimed (unverified)
PT Intraco Penta TbkIndonesiaOther9/1/2026◌ Claimed (unverified)
🔒 Entidad no identificada—Other9/1/2026◌ Claimed (unverified)
THQ NordicSwedenMedia & entertainment8/30/2026◌ Claimed (unverified)
Erdem Hospital—Healthcare8/30/2026◌ Claimed (unverified)
Hospital Clínico Universidad de ChileChileHealthcare8/30/2026◌ Claimed (unverified)
National Kidney RegistryUnited StatesHealthcare8/25/2026◌ Claimed (unverified)
Studio Legale ESEItalyLegal8/25/2026◌ Claimed (unverified)
🔒 Entidad no identificada—Other8/21/2026◌ Claimed (unverified)

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.