GBHackers

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption


Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data theft with file encryption.

Documented by CyberXtron, its dedicated leak site was first observed active on August 5, 2026, and its early victim list includes organizations in technology, manufacturing, government, agriculture, energy, education, and retail.

The listed victims are distributed across Thailand, Italy, Indonesia, Serbia, Curaçao, South Korea, Spain, the Czech Republic, Germany, Nigeria, and Switzerland.

Thailand accounts for three reported victims, while Italy, Indonesia, and Serbia each account for two. Technology organizations represent the largest identified sector, with four victims, followed by manufacturing with three.

New Panzer Ransomware Hits 16 Victims

The distribution indicates broad, opportunistic targeting rather than a tightly focused geographic or industry campaign. Government and defense, agriculture and food production, utilities, education, and commercial organizations have also appeared among the group’s reported targets.

Panzer operates a semi-open affiliate program, recruiting prospective partners through a Tox-based application process. Affiliates must reportedly pass a screening before receiving dashboard access.

Panzer Ransomware (Source: cyberxtron)

The group offers an 80/20 revenue model, with affiliates retaining 80% of ransom payments and Panzer taking a 20% platform fee.

Notably, the service advertises ransomware builds for Windows, Linux, VMware ESXi, and FreeBSD. This cross-platform capability increases the risk to enterprise environments, particularly organizations running mixed server fleets and virtualized infrastructure.

ESXi support can be especially disruptive because a successful attack against a hypervisor may encrypt multiple virtual machines and critical business services.

Panzer’s affiliate dashboard appears designed for scalable criminal operations. Advertised functions include balance tracking, build management, support tickets, team sub-accounts, and a leak-publication workflow requiring approval before victim data is posted.

Cyberxtron stated that the operators additionally claim to monitor newly onboarded affiliates during their first month to detect possible researcher or law-enforcement activity.

Panzer Ransomware (Source: cyberxtron)
Panzer Ransomware (Source: cyberxtron)

Accounts that show no activity during the first week may be automatically deactivated, suggesting a platform that is intended to retain active operators rather than support one-off attacks. No independently verified initial-access technique has been attributed to Panzer.

However, associated activities assessed with medium-to-low confidence include OS credential dumping, brute-force attacks, network service discovery, use of valid accounts, remote service lateral movement, and attempts to impair security tools.

Panzer follows a double-extortion model: attackers allegedly exfiltrate sensitive corporate files and customer data before encrypting systems, then use public posts on leak sites and countdown pressure to force payment. No verified malware hashes, IP addresses, domains, or samples have been publicly confirmed.

Organizations should prioritize patching internet-facing systems, enforcing phishing-resistant MFA, segmenting critical infrastructure, monitoring for unusual outbound transfers, and maintaining immutable offline backups.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection



Source link