Panzer: New Cross-Platform RaaS Claims Global Victims in Its First Month
A newly emerged Ransomware-as-a-Service operation listed 20+ victims across 10+ countries in its first month, with an ESXi build that can encrypt an entire hypervisor in one action.
First Seen: August 5, 2026
Targeted Regions: Spain, Portugal, France, Saudi Arabia, Germany, Indonesia, Serbia, Italy, South Korea, Czech Republic, India, Thailand, Nigeria
Targeted Platforms: Windows, Linux, VMware ESXi, FreeBSD
Targeted Industries: Technology, Manufacturing, Government, Food Production, Energy & Utilities, Education, Retail & E-Commerce, Telecommunications, Construction & Engineering, Media, Gaming
Malware: Panzer ransomware
Attack: Panzer is a newly emerged Ransomware-as-a-Service operation whose dedicated leak site was first observed active on August 5, 2026. Within its first month the group listed 20+ claimed victims across 10+ countries, pairing data theft with file encryption in a double-extortion model and pressuring victims through a Tor leak site with countdown timers. The operation advertises cross-platform payloads for Windows, Linux, VMware ESXi and FreeBSD, with the ESXi build posing the greatest risk since a compromised hypervisor allows encryption of many virtual machines in a single action. Panzer runs a semi-open affiliate programme with Tox-based screening, an 80/20 revenue split favouring affiliates, and a fully featured dashboard for build management, negotiation and leak publication. No encryptor sample has been publicly analysed and no file hashes or network infrastructure have been verified; the only public indicators are the leak-site onion address and affiliate Tox ID, initial access vectors remain unconfirmed, and all victim listings remain attacker claims except one publicly confirmed incident.
Attack Details
Recommendations
Deploy detection rules for vssadmin delete shadows, wmic shadowcopy delete and bcdedit recoveryenabled no. Treat any execution on a server as imminent encryption: isolate the host automatically, preserve evidence and open an incident rather than a ticket.
Add the published .onion leak-site address and affiliate Tox ID to threat-intelligence monitoring and alert on any connection attempts from internal assets. Because no file hashes, domains or IP addresses have been verified, do not rely on blocklists for this threat.
Baseline the approved remote-management stack and alert on ScreenConnect, AnyDesk or similar agents appearing outside change control, on PsExec service installations, and on RMM execution combined with mass archive creation and admin-share activity in a compressed window.
Alert on archives larger than 100 MB appearing in user profiles or ProgramData, on rclone, 7-Zip, WinRAR, MEGA or anonymous file-transfer processes running on servers, and on large or unusual outbound transfers to non-corporate cloud storage.
Deploy endpoint detection with tamper protection across every platform Panzer advertises a build for, and alert on service-stop attempts against EDR or antivirus agents.
Keep immutable, offline or air-gapped backups for Windows, Linux, ESXi and FreeBSD workloads held outside the virtual estate, and rehearse restoration against a hypervisor-level failure rather than a single file server.
Potential MITRE ATT&CK TTPs
Indicators of Compromise (IOCs)
| Type | Value |
|---|---|
| TOR Address | pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion |
| Tox ID | 8C3D96497A9438794F705C055FC2FD3059F6CF11FF51060EE55ED7F0679CFC7218825BD56CB1 |
Recent Breaches
- aemet.es
- aqualogus.pt
- kafec.sa
- hs-heilbronn.de
- diskominfo.go.id
- senvibe.com
- vojvodina.gov.rs
- nteitalia.it
- frisianflag.com
- jccm.es
- doimocucine.com
- dle.co.kr
- sagasta.cz
- alpine-electronics.eu
- xpresstech.in
- minorfood.com
- siamoil.com
- dailytrust.com
- unsa.ac.id
- festinagroup.com
References
- andreafortuna.org — Panzer ransomware: Italian victims
- cyberxtron.com — Panzer ransomware profile
- kobaran.com — Panzer ransomware emerges as a full affiliate platform
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
