direwolf
RansomwareAbout the group
Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Impact and victims
The group direwolf has 9 known ransomware victims. See the most affected sectors and countries and recent victims.
9known victims
9in Brazil
4sectors hit
Activity (12 months)
Most attacked sectors
Professional Services3
Technology2
Transportation2
Healthcare1
Most affected countries
🇧🇷 Brasil9
Recent victims
Softruck
Oportunidados
TOTVS
Chat Jurídico
Clínica Vida
Clemar Assessoria e Logística em Comércio Internacional
Transpedrosa
Aroeira Salles Advogados
Faria Braga Advogados Associados
direwolf uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →