Italian ransomware activity is accelerating, and a new ransomware-as-a-service (RaaS) group called Panzer has quickly entered the spotlight.
Ransomfeed reported 212 claimed attacks against Italian organizations by early September 2026, already higher than the 169 claims recorded during all of 2025.
Panzer appeared on August 5, 2026, with a leak site and an affiliate-focused platform. Within its first month, the group claimed between 16 and 19 victims across 11 countries.
Two alleged victims were Italian organizations: Treviso-based kitchen manufacturer Doimo Cucine and telecommunications engineering company NTE Italia in Catanzaro.
Doimo Cucine was listed on Panzer’s leak site on August 17, with attackers claiming to have stolen 30 GB of data. NTE Italia was posted four days later, with a claimed 16 GB of sensitive documents.
Neither company has publicly confirmed the incidents. Leak-site posts remain attacker claims and should not be treated as verified evidence of compromise.
Panzer Ransomware Hits Enterprises
Panzer stands out because of its reportedly mature affiliate platform, despite having no publicly analyzed ransomware sample.
The group is believed to use a semi-open RaaS model in which affiliates apply through Tox messaging and undergo screening before gaining access.
The platform reportedly gives affiliates an 80 percent share of ransom payments, while Panzer operators receive 20 percent.
It also includes automated Bitcoin invoice generation, revenue tracking, victim negotiation chats, leak-publication tools, support tickets, and sub-account management for affiliate teams.
Panzer’s operators reportedly deactivate accounts after more than seven days of inactivity. They also claim to monitor new affiliates during their first month to identify researchers or law-enforcement infiltration attempts.
This shows that Panzer is trying to operate like a managed criminal service rather than a small ransomware gang.
The operation advertises payload builds for Windows, Linux, VMware ESXi, and FreeBSD. This cross-platform support increases risk for enterprises with mixed server environments.
ESXi support is particularly serious because a compromised hypervisor can allow attackers to encrypt many virtual machines at once, disrupting dozens of business services from a single point of failure.
Panzer uses the double-extortion model: attackers allegedly steal data before encrypting systems, then threaten to publish the stolen information if the victim refuses to pay.
Strong backups can help restore encrypted systems, but they cannot prevent stolen documents, customer information, engineering files, or network data from being exposed.
| Category | Details |
|---|---|
| Ransomware group | Panzer ransomware |
| Operational model | Ransomware-as-a-Service (RaaS) with affiliate recruitment and revenue-sharing |
No verified Panzer malware hashes, command-and-control servers, or network indicators have been published. Defenders should therefore focus on behavior rather than file-based detection.
Suspected activity includes credential dumping, brute-force attacks, remote-service abuse, network discovery, data collection, exfiltration, and attempts to disable security tools, andreafortuna said.
High-risk warning signs include unusual VPN logins, newly created administrator accounts, unexpected RMM tools such as ScreenConnect or AnyDesk, large archive files in user folders or ProgramData, Rclone execution, and unusual outbound transfers to cloud-storage services.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN
