Dire Wolf Ransomware Attacks: How to Test and Strengthen Your Defenses
| October 09, 2026
Key Takeaways
- Dire Wolf is a double-extortion ransomware that claimed 100 victims across 32 countries by August 2026.
- Before encryption, Dire Wolf kills the Event Log service, deletes shadow copies and backups, and disables Windows Recovery.
- Its Go-based encryptor gives each file a unique ChaCha20 key derived through Curve25519 and SHA-256.
- The Picus Platform simulates Dire Wolf Ransomware across endpoint, network, and email attack modules to test security controls.
Dire Wolf Ransomware is a double-extortion ransomware first observed in April 2025. By August 2026, it had claimed 100 victims across 32 countries, including the United States and Brazil, mainly in professional services, manufacturing, healthcare, technology, and financial services.
Its Go-based, UPX-packed encryptor gives every file a unique ChaCha20 key derived through Curve25519 and SHA-256, and encrypts only the first 1 MB of larger files for speed. Before encryption, it kills the Event Log service, deletes shadow copies and backups, disables Windows Recovery, and stops up to 75 services [1]. Afterward, it forces a reboot and deletes itself.
In this blog, we will explain how Dire Wolf Ransomware works and show how Picus helps you test your security controls against this threat.
Dire Wolf Ransomware at a Glance
|
Field |
Detail |
|
Malware type |
Ransomware |
|
Earliest recorded attack |
17 April 2025 |
|
Platform |
Windows |
|
Language and packing |
Go, typically packed with UPX |
|
Initial access |
Suspected phishing, exposed RDP or VPN access, compromised credentials, or third-party access [1] |
|
File encryption |
Curve25519 key exchange, SHA-256 derivation, and ChaCha20 encryption with a separate key for each file |
|
Encryption scope |
Full encryption below 1 MB; encryption of the first 1 MB for files above 1 MB [1] |
|
Encrypted-file extension |
.direwolf |
|
Recovery disruption |
Shadow-copy deletion, backup removal, recovery-setting changes, and process and service termination |
|
Ransom note |
HowToRecoveryFiles.txt, with victim-specific chat access details |
What Is Dire Wolf Ransomware?
Dire Wolf is a Windows ransomware family used by a human-operated group of the same name. The operators steal sensitive data before encrypting files, then threaten to publish that data on a Tor-hosted leak site unless the victim pays.
The encryptor uses Go and typically arrives as a UPX-packed binary. Its main job is to make files inaccessible quickly, but it also stops services, removes local recovery options, suppresses event logging, and deletes itself.
Dire Wolf's earliest recorded attack dates to 17 April 2025. The group posted its first six victims on 26 May 2025, and its leak site listed 100 victims across 32 countries by 19 August 2026. Professional services, manufacturing, healthcare, technology, and financial services accounted for the largest victim groups [1].
How Does Dire Wolf Ransomware Work?
Initial Access and Data Theft
Dire Wolf’s initial access methods remain uncertain. Suspected routes include spearphishing attachments, exposed RDP or VPN services, compromised accounts, and access through a third party or managed service provider. Dire Wolf has not been linked to the exploitation of any specific CVE.
Once inside, the operators spend days to weeks in the environment and steal sensitive data before encryption. Average exfiltration volume across the described incidents was approximately 265 GB, while typical ransom demands were around USD 500,000 and varied with the victim’s size [1].
Startup Checks and Execution
The Go encryptor typically uses UPX packing. Although the language supports cross-platform development, the documented Dire Wolf encryptors target Windows.
At launch, the malware checks for the system-wide mutex Global\direwolfAppMutex and the file C:\runfinish.exe [1]. If either exists, the binary logs the condition, deletes itself, and exits. These checks prevent another encryption run on a host that is already running the malware or has completed a previous run.
The encryptor takes its settings from command-line flags rather than a configuration file. The -d flag selects a specific directory, while -h requests help.
Defense Impairment and Recovery Disruption
After the startup checks pass, Dire Wolf attacks logging and recovery mechanisms before encrypting files. It uses WMI queries to find the process hosting the Windows Event Log service, then repeatedly terminates it with taskkill.
The malware later uses wevtutil cl to clear the Application, System, Security, and Setup logs:
|
wevtutil cl Application wevtutil cl System wevtutil cl Security wevtutil cl Setup |
Dire Wolf also deletes Volume Shadow Copies, removing local snapshots that could otherwise help restore earlier versions of files. It uses both vssadmin and wmic for this purpose:
|
vssadmin delete shadows /all /quiet wmic shadowcopy delete /nointeractive |
The malware then targets Windows Server Backup with wbadmin [1]:
|
# Stop the active backup job. wbadmin stop job # Disable backup scheduling. wbadmin disable backup # Request deletion with no backup versions retained. wbadmin delete backup -keepVersions:0 # Request deletion of system-state backups. wbadmin delete systemstatebackup # Delete the backup catalog used to locate backups. wbadmin delete catalog |
Dire Wolf changes boot settings through bcdedit to inhibit automatic recovery:
|
# Disable recovery for the default boot entry. bcdedit /set {default} recoveryenabled No # Ignore boot failures that would otherwise trigger recovery handling. bcdedit /set {default} bootstatuspolicy ignoreallfailures |
The encryptor also forcibly stops processes and services associated with databases, mail, virtualization, backup, and security software. These include sqlservr.exe, vss.exe, outlook.exe, VeeamTransportSvc, BackupExecJobEngine, and SQLSERVERAGENT. Stopping these components can release files held open by applications and interrupt backup or protection activity.
Together, these actions reduce the victim’s ability to recover locally and remove useful event history.
File Encryption
Dire Wolf generates a random private key for each file and performs a Curve25519 key exchange using a public key embedded in the binary. It passes the resulting shared secret through SHA-256 to derive the key and nonce used by ChaCha20.
The encryptor uses size-based partial encryption to reduce the time spent on large files. It fully encrypts files smaller than 1 MB, but encrypts only the first 1 MB of files larger than that threshold.
After its startup checks, the encryptor waits two seconds and creates a pool of goroutine workers sized at eight times th e host’s logical CPU count. This lets it process multiple files concurrently and continue working while other operations wait on disk I/O.
Dire Wolf appends .direwolf to encrypted filenames. It skips .exe, .dll, .sys, .drv, .bin, .tmp, .iso, .img, and .direwolf files. These exclusions avoid reprocessing files carrying its own extension and reduce damage to system components, helping the host remain usable enough to display the ransom demand [1].
Ransom Notes and Cleanup
When encryption finishes, Dire Wolf writes C:\runfinish.exe as a completion marker and drops HowToRecoveryFiles.txt into every affected directory. The ransom note contains a hardcoded, victim-specific chat room identifier and login credentials for direct negotiation with the operators.
The ransomware then schedules a forced reboot with shutdown:
|
# Force applications to close and restart the host after ten seconds. shutdown -r -f -t 10 |
Shortly afterward, the encryptor uses del commands to remove its executable from disk.
How Picus Simulates Dire Wolf Ransomware Attacks
We strongly suggest simulating Dire Wolf Ransomware Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other ransomware variants, such as Warlock, BlackCat, Black Basta, and Akira, within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for the Dire Wolf Ransomware Attacks:
|
Threat ID |
Threat Name |
Attack Module |
|
57375 |
Dire Wolf Ransomware Campaign |
Windows Endpoint |
|
61235 |
Dire Wolf Ransomware Download Threat |
Network Infiltration |
|
40662 |
Dire Wolf Ransomware Email Threat |
E-mail Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.
References
[1] Smarttech247, "DireWolf Ransomware Threat Report," Smarttech247 Threat Intelligence. Accessed: Oct. 6, 2026. [Online]. Available: https://www.smarttech247.com/threat-intel-reports/direwolf-ransomware-threat-report
