Dire Wolf is a double-extortion data-theft group that has been active since May 2025. It is written in Go, targets various sectors, and combines encryption with data exfiltration to extort victims.
On November 13, 2025, the Dire Wolf ransomware group claimed to have compromised Coral, C.A., a Venezuelan distributor. The threat actor claimed to have stolen 160 GB of confidential information, including financial, sales, and billing data, as well as a Microsoft SQL Server database. The group threatened to publish the stolen data starting on November 15, 2025. It has not yet been verified whether the data was ultimately leaked or whether the company suffered any financial losses.