Dire Wolf Ransomware Attacks: How to Test and Strengthen Your Defenses

Umut Bayram | 6 MIN READ

| October 09, 2026

Key Takeaways

  • Dire Wolf is a double-extortion ransomware that claimed 100 victims across 32 countries by August 2026.
  • Before encryption, Dire Wolf kills the Event Log service, deletes shadow copies and backups, and disables Windows Recovery.
  • Its Go-based encryptor gives each file a unique ChaCha20 key derived through Curve25519 and SHA-256.
  • The Picus Platform simulates Dire Wolf Ransomware across endpoint, network, and email attack modules to test security controls.

Dire Wolf Ransomware is a double-extortion ransomware first observed in April 2025. By August 2026, it had claimed 100 victims across 32 countries, including the United States and Brazil, mainly in professional services, manufacturing, healthcare, technology, and financial services.

Its Go-based, UPX-packed encryptor gives every file a unique ChaCha20 key derived through Curve25519 and SHA-256, and encrypts only the first 1 MB of larger files for speed. Before encryption, it kills the Event Log service, deletes shadow copies and backups, disables Windows Recovery, and stops up to 75 services [1]. Afterward, it forces a reboot and deletes itself.

In this blog, we will explain how Dire Wolf Ransomware works and show how Picus helps you test your security controls against this threat.

Dire Wolf Ransomware at a Glance

Field

Detail

Malware type

Ransomware

Earliest recorded attack

17 April 2025

Platform

Windows

Language and packing

Go, typically packed with UPX

Initial access

Suspected phishing, exposed RDP or VPN access, compromised credentials, or third-party access [1]

File encryption

Curve25519 key exchange, SHA-256 derivation, and ChaCha20 encryption with a separate key for each file

Encryption scope

Full encryption below 1 MB; encryption of the first 1 MB for files above 1 MB [1]

Encrypted-file extension

.direwolf

Recovery disruption

Shadow-copy deletion, backup removal, recovery-setting changes, and process and service termination

Ransom note

HowToRecoveryFiles.txt, with victim-specific chat access details

What Is Dire Wolf Ransomware?

Dire Wolf is a Windows ransomware family used by a human-operated group of the same name. The operators steal sensitive data before encrypting files, then threaten to publish that data on a Tor-hosted leak site unless the victim pays.

The encryptor uses Go and typically arrives as a UPX-packed binary. Its main job is to make files inaccessible quickly, but it also stops services, removes local recovery options, suppresses event logging, and deletes itself.

Dire Wolf's earliest recorded attack dates to 17 April 2025. The group posted its first six victims on 26 May 2025, and its leak site listed 100 victims across 32 countries by 19 August 2026. Professional services, manufacturing, healthcare, technology, and financial services accounted for the largest victim groups [1].

How Does Dire Wolf Ransomware Work?

Initial Access and Data Theft

Dire Wolf’s initial access methods remain uncertain. Suspected routes include spearphishing attachments, exposed RDP or VPN services, compromised accounts, and access through a third party or managed service provider. Dire Wolf has not been linked to the exploitation of any specific CVE.

Once inside, the operators spend days to weeks in the environment and steal sensitive data before encryption. Average exfiltration volume across the described incidents was approximately 265 GB, while typical ransom demands were around USD 500,000 and varied with the victim’s size [1].

Startup Checks and Execution

The Go encryptor typically uses UPX packing. Although the language supports cross-platform development, the documented Dire Wolf encryptors target Windows.

At launch, the malware checks for the system-wide mutex Global\direwolfAppMutex and the file C:\runfinish.exe [1]. If either exists, the binary logs the condition, deletes itself, and exits. These checks prevent another encryption run on a host that is already running the malware or has completed a previous run.

The encryptor takes its settings from command-line flags rather than a configuration file. The -d flag selects a specific directory, while -h requests help.

Defense Impairment and Recovery Disruption

After the startup checks pass, Dire Wolf attacks logging and recovery mechanisms before encrypting files. It uses WMI queries to find the process hosting the Windows Event Log service, then repeatedly terminates it with taskkill.

The malware later uses wevtutil cl to clear the Application, System, Security, and Setup logs:

wevtutil cl Application

wevtutil cl System

wevtutil cl Security

wevtutil cl Setup

Dire Wolf also deletes Volume Shadow Copies, removing local snapshots that could otherwise help restore earlier versions of files. It uses both vssadmin and wmic for this purpose:

vssadmin delete shadows /all /quiet

wmic shadowcopy delete /nointeractive

The malware then targets Windows Server Backup with wbadmin [1]:

# Stop the active backup job.

wbadmin stop job

# Disable backup scheduling.

wbadmin disable backup

# Request deletion with no backup versions retained.

wbadmin delete backup -keepVersions:0

# Request deletion of system-state backups.

wbadmin delete systemstatebackup

# Delete the backup catalog used to locate backups.

wbadmin delete catalog

Dire Wolf changes boot settings through bcdedit to inhibit automatic recovery:

# Disable recovery for the default boot entry.

bcdedit /set {default} recoveryenabled No

# Ignore boot failures that would otherwise trigger recovery handling.

bcdedit /set {default} bootstatuspolicy ignoreallfailures

The encryptor also forcibly stops processes and services associated with databases, mail, virtualization, backup, and security software. These include sqlservr.exe, vss.exe, outlook.exe, VeeamTransportSvc, BackupExecJobEngine, and SQLSERVERAGENT. Stopping these components can release files held open by applications and interrupt backup or protection activity.

Together, these actions reduce the victim’s ability to recover locally and remove useful event history.

File Encryption

Dire Wolf generates a random private key for each file and performs a Curve25519 key exchange using a public key embedded in the binary. It passes the resulting shared secret through SHA-256 to derive the key and nonce used by ChaCha20.

The encryptor uses size-based partial encryption to reduce the time spent on large files. It fully encrypts files smaller than 1 MB, but encrypts only the first 1 MB of files larger than that threshold.

After its startup checks, the encryptor waits two seconds and creates a pool of goroutine workers sized at eight times th e host’s logical CPU count. This lets it process multiple files concurrently and continue working while other operations wait on disk I/O.

Dire Wolf appends .direwolf to encrypted filenames. It skips .exe, .dll, .sys, .drv, .bin, .tmp, .iso, .img, and .direwolf files. These exclusions avoid reprocessing files carrying its own extension and reduce damage to system components, helping the host remain usable enough to display the ransom demand [1].

Ransom Notes and Cleanup

When encryption finishes, Dire Wolf writes C:\runfinish.exe as a completion marker and drops HowToRecoveryFiles.txt into every affected directory. The ransom note contains a hardcoded, victim-specific chat room identifier and login credentials for direct negotiation with the operators.

The ransomware then schedules a forced reboot with shutdown:

# Force applications to close and restart the host after ten seconds.

shutdown -r -f -t 10

Shortly afterward, the encryptor uses del commands to remove its executable from disk.

How Picus Simulates Dire Wolf Ransomware Attacks

We strongly suggest simulating Dire Wolf Ransomware Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other ransomware variants, such as Warlock, BlackCat, Black Basta, and Akira, within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for the Dire Wolf Ransomware Attacks:

Threat ID

Threat Name

Attack Module

57375

Dire Wolf Ransomware Campaign

Windows Endpoint

61235

Dire Wolf Ransomware Download Threat

Network Infiltration

40662

Dire Wolf Ransomware Email Threat

E-mail Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.

References

[1] Smarttech247, "DireWolf Ransomware Threat Report," Smarttech247 Threat Intelligence. Accessed: Oct. 6, 2026. [Online]. Available: https://www.smarttech247.com/threat-intel-reports/direwolf-ransomware-threat-report

 
 
Dire Wolf is a Windows ransomware family used by a human-operated group of the same name. It follows a double-extortion model, stealing sensitive data before encrypting files and threatening to publish that data on a Tor-hosted leak site unless the victim pays. Its earliest recorded attack dates to 17 April 2025.
By 19 August 2026, Dire Wolf had listed 100 victims across 32 countries on its leak site, including organizations in the United States and Brazil. Professional services, manufacturing, healthcare, technology, and financial services accounted for the largest victim groups.
Dire Wolf's initial access methods remain uncertain. Suspected routes include spearphishing attachments, exposed RDP or VPN services, compromised accounts, and access through a third party or managed service provider. Dire Wolf has not been linked to the exploitation of any specific CVE.
Dire Wolf generates a random private key for each file and performs a Curve25519 key exchange with a public key embedded in the binary. The shared secret passes through SHA-256 to derive the ChaCha20 key and nonce. Files under 1 MB are fully encrypted, while larger files have only their first 1 MB encrypted.
Typical Dire Wolf ransom demands are around USD 500,000 and vary with the victim's size. Before encryption, operators spend days to weeks in the environment and exfiltrate approximately 265 GB of data on average across described incidents.
Protection starts with securing the entry points Dire Wolf is suspected of abusing, including phishing attachments, exposed RDP or VPN services, compromised credentials, and third-party access. Organizations should also validate that security controls catch shadow-copy deletion, backup removal, event log clearing, and mass service termination before encryption begins.
The Picus Platform simulates Dire Wolf Ransomware attacks to test the effectiveness of security controls. Picus Threat Library includes the Dire Wolf Ransomware Campaign for Windows Endpoint, the Dire Wolf Ransomware Download Threat for Network Infiltration, and the Dire Wolf Ransomware Email Threat for E-mail Infiltration.

Table of Contents

Ready to start? Request a demo