The Cyber Security Agency of Singapore (CSA) is warning organizations about the Dire Wolf ransomware group , which has launched targeted attacks on the manufacturing and technology sectors. The ransomware was first detected in May 2025 and affected 16 organizations within the first month.

The Dire Wolf group uses a dual-extortion. It encrypts victims’ systems while simultaneously threatening to leak stolen data via a public data leakage site (DLS). The group also uses analysis evasion techniques and multi-layered attack chains, designed to verify encryption success, evade detection, and thwart recovery efforts. This dual threat amplifies both data loss and reputational damage for affected organizations.
See also: The Evolution of Ransomware and Attackers' New Tools
Dire Wolf Ransomware
The analysis of the Dire Wolf ransomware was performed by Trustwave, using a sample obtained through Virustotal Hunting. The analysis revealed that the malware was initially bundled with UPX to prevent analysis. Later, it appeared as a Golang-based binary.
Once executed, Dire Wolf checks for previous infection, using a marker file ("runfinish.exe") or a mutex ("Global\direwolfAppMutex"). It then disables Windows event logging, attempts to stop 75 targeted services, including security solutions such as Sophos and Symantec, and terminates 59 processes associated with databases, productivity tools , and antivirus software.

The ransomware also executes commands to delete backups, and clear event logs, making recovery significantly more complicated. It is additionally equipped with strong Curve25519 and ChaCha20 encryption and displays a custom ransom note containing unique victim credentials. The ransom demands are high, reaching up to $500,000.
See also: Hackers use legitimate drivers to shut down antiviruses
“Dire Wolf has already affected at least 16 victims in 11 countries, including the US, Thailand, Taiwan, Singapore, Italy and India. The manufacturing and technology sectors face the highest risk, including data processing, e-invoicing and privacy service providers in Asia and globally. Also sensitive customer data at risk,” said Pareekh Jain, CEO of EIIRTrend & Pareekh Consulting.
Dire Wolf Ransomware: Impact on Global Businesses
“His attacks are directly disrupting operations and supply chains, particularly in the manufacturing and technology sectors, leading to production delays, revenue losses and customer impact,” said Manish Rawat, analyst at TechInsights. “The economic impact is significant, with ransom demands reaching into the mid-six-figure range, putting pressure on large enterprises.”
Rawat added that beyond downtime, public data leaks cause reputational damage and can lead to penalties for companies. Finally, rapid, targeted campaigns strain the resources of network defenders, forcing organizations to shift their focus from long-term resilience to address the immediate crisis.
Where defenses fail
The Dire Wolf ransomware group targets points that many businesses consider data.
Rawat said organizations still underestimate the risk of lateral movement within their networks once a single endpoint is compromised. Dire Wolf's Golang code can spread quickly across platforms. There is also little attention to recovery mechanisms beyond simple backups. Ransomware, however, disables snapshots, shadow copies, and automated recovery routines.
Επιπλέον, το αδύναμο credential hygiene και η μη ετοιμότητα για phishing επιθέσεις καθιστούν την είσοδο των hackers εύκολη (μέσω συνημμένων phishing και credential stuffing), ειδικά όπου λείπει η πολυπαραγοντική ταυτοποίηση.
See also: SonicWall: Disable SSL VPN due to ransomware
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The CSA has advised administrators to monitor their systems and networks for the reported IOCs and check event and security logs for suspicious activity. They should also ensure that multiple backups and implement appropriate controls to detect and mitigate ransomware.
Businesses should also adopt a proactive, multi-layered defense against ransomware, going beyond standard backups and updates.
“Third-party risk management is critical, requiring MSPs and vendors to meet the same security standards. Additionally, proactive threat hunting and intelligence sharing help detect emerging threats, like Dire Wolf, before they escalate,” said Rawat.
Businesses must treat ransomware both as a technical and a business risk and be prepared for system recovery as well as for the impact on reputation and regulatory compliance.
