Human-operated ransomware group using custom Go-based ransomware to target global sectors.
Analyst brief
Direwolf is a human-operated ransomware operation active since May 2025, targeting technology, healthcare, financial services, and manufacturing sectors across 13+ countries including the US, Brazil, UK, and India. TTPs involve custom ransomware written in Golang using Curve25519 and ChaCha20 encryption, operated by a tight core team rather than a broad affiliate model. Defenders should focus on detecting lateral movement and targeting patterns against listed sectors, especially for Go-based activity.
direwolf
activecrime
Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.