Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Turkey

Dire Wolf

Also known asdire_wolf

Dire Wolf is a human-operated ransomware operation first documented in May 2025 and linked to targeted, financially motivated intrusions. The group uses a double-extortion model, combining system encryption with the threat of data exposure, and operates a dedicated dark web leak site where victim disclosures are published in batches. Victims are directed to one-to-one negotiation via Tox, with staged deadlines and escalation through the leak site if negotiations fail. Reported victim activity spans multiple regions and sectors, with technology and manufacturing organizations repeatedly appearing; one source also characterized the group as having an Asia/Italy focus. Technically, Dire Wolf uses a Go-based Windows encryptor, commonly delivered as a UPX-packed executable. The malware uses a system-wide mutex and a local marker file to avoid redundant execution, encrypts local storage and accessible network resources, applies exclusions to preserve basic OS operability, and appends the .direwolf extension to encrypted files. Its encryption design uses Curve25519-based key exchange with ChaCha20 for file encryption, generating per-file session keys; smaller files are fully encrypted while larger files may be partially encrypted for speed. After encryption, it commonly drops a ransom note named HowToRecoveryFiles.txt, may record local completion state, self-delete, and in some cases trigger a forced reboot. Intrusions may also include pre-encryption steps intended to weaken recovery options, including disruption of backup and recovery capabilities and suppression or disabling of Windows event logging. Dire Wolf has also been observed in intrusion contexts involving the EDR killer SmilingKiller. ESET reported SmilingKiller during LockBit and Dire Wolf intrusions and noted that it uses control-flow flattening and was inspired by kill-floor while switching the abused driver to K7RKScan.sys. Aliases directly reflected in the content: dire_wolf.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics11 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0005
Stealth
2 techniques
T1027
Obfuscated Files or Information
T1027.005
Indicator Removal from Tools
T1070
Indicator Removal
T1070.001
Clear Windows Event Logs
T1070.004
File Deletion
TA0011
Command and Control
1 technique
T1071
Application Layer Protocol
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
TA0040
Impact
4 techniques
T1486×2
Data Encrypted for Impact
T1489
Service Stop
T1490
Inhibit System Recovery
T1529
System Shutdown/Reboot
ACTIVITY FEED

Recent activity

9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping12

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.