direwolf Unknown

First seen: 09/01/2026 19:22 Last Attack: 13/01/2026
5
Total Victims
0
Victims (30d)
Details

Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.

Leak Site

Onion URL: http://direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion

Victims by Country
🇲🇾 Malaysia 2
🇯🇵 Japan 1
🇦🇪 UAE 1
🇩🇪 Germany 1
Ransomware Victims 5
Victim Country Sector Discovered
Tepco-Group 🇯🇵 JP Energy 13/01/2026 16:45
13/01/2026
Perdana Petroleum Berhad 🇲🇾 MY Energy 13/01/2026 16:44
13/01/2026
Chemsain Konsultant Sdn Bhd 🇲🇾 MY Manufacturing 13/01/2026 16:43
13/01/2026
Bauerfeind 🇩🇪 DE Healthcare 09/01/2026 19:23
09/01/2026
Mohammad Omar Bin Haider Holding Group 🇦🇪 AE Not Found 09/01/2026 19:22
09/01/2026
Metadata

Slug: direwolf

Created: 14/01/2026 08:19

Updated: 28/06/2026 16:02