werewolves is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 26 public victims claimed by this operator between December 20, 2023 and March 13, 2024. The Werewolves ransomware group is a relatively new financially-motivated cybercriminal organization that emerged in December 2023, with limited public documentation available from major threat intelligence sources. Based on available targeting data, the group appears to operate with a focus on business services and manufacturing sectors, having compromised 26 known victims across multiple countries including Russia, the United States, Netherlands, Germany, and France. The group's targeting pattern suggests they may employ opportunistic attack vectors rather than highly sophisticated initial access methods, though specific technical details about their encryption methods, data exfiltration practices, or operational structure remain undocumented by major security research organizations. Due to the group's recent emergence and relatively small victim count, there are no publicly reported high-profile campaigns or significant law enforcement actions against them. The current operational status of Werewolves remains unclear given the limited threat intelligence reporting available from established cybersecurity firms and government agencies.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.