Dire Wolf Ransomware: Threat Combining Data Encryption and Leak Extortion
Essential information
- Published
- 03/09/2025 17:31
- Modified
- 03/09/2025 20:14
- Tags
- 2025-09-03 anti-recovery chacha20 curve25519 data leakage dire wolf double-extortion encryption ransomware self-deletion
- Related entities
- 2 observables, 1 intrusion sets (apt), 7 techniques (mitre), 1 malware, 9 others
Description
The DireWolf ransomware group emerged in May 2025, targeting various industries globally. They employ a double extortion technique, encrypting data and threatening leaks. The ransomware uses Curve25519 key exchange and ChaCha20 encryption, generating unique keys for each file. It implements anti-recovery measures, terminating backup processes, deleting logs, and disabling recovery environments. The malware encrypts files, creates ransom notes, and self-deletes after scheduling a system reboot. DireWolf's sophisticated approach, combining encryption, anti-analysis techniques, and data leakage threats, poses a significant risk to organizations across sectors.