Panzer Ransomware Targets 16 Organizations Across 11 Countries in Double-Extortion Attacks | #ransomware | #cybercrime


A newly identified ransomware operation known as Panzer has allegedly listed 16 victims across 11 countries, signaling the arrival of another ransomware-as-a-service (RaaS) platform built to support affiliate-driven double-extortion campaigns.

Documented by CyberXtron, Panzer’s dedicated leak portal was first observed active on August 5, 2026. The group has since named organizations spanning technology, manufacturing, government, agriculture, energy, education, retail, and other commercial sectors.

The alleged victim list includes organizations in Thailand, Italy, Indonesia, Serbia, Curaçao, South Korea, Spain, the Czech Republic, Germany, Nigeria, and Switzerland.

Thailand accounts for three reported victims, while Italy, Indonesia, and Serbia each account for two. Technology organizations make up the largest identified sector, with four reported victims, followed by manufacturing with three.

Panzer Ransomware Targets 16 Organizations

Panzer’s early activity indicates opportunistic targeting rather than a campaign focused on a single country, vertical, or type of organization.

The presence of alleged victims in government and defense, agriculture and food production, utilities, educational institutions, and commercial enterprises suggests that affiliates may be free to pursue a broad range of targets.

Panzer Ransomware (Source: cyberxtron)

The operation appears to follow the established double-extortion playbook. Attackers allegedly steal sensitive corporate information and customer data, then encrypt systems and threaten to disclose it via a leak site if the targeted organization refuses to pay.

This approach increases the pressure on victims because recovering encrypted files from backups may not resolve the risk of data exposure, regulatory scrutiny, litigation, or reputational damage.

Panzer is reportedly operating a semi-open affiliate program that recruits partners through a Tox-based application process. Prospective affiliates must pass a screening stage before they are granted access to the platform’s dashboard.

The group advertises an 80/20 revenue-sharing arrangement, allowing affiliates to retain 80% of collected ransom payments while Panzer operators receive a 20% platform fee.

This model resembles other RaaS ecosystems, including VanHelsing, where developers provide ransomware infrastructure and affiliates conduct intrusions. Panzer’s dashboard is designed to support scalable criminal operations.

Advertised capabilities include ransom balance tracking, ransomware build management, support-ticket functions, team sub-accounts, and a workflow for publishing stolen victim data. Leak posts reportedly require approval before publication.

CyberXtron also reported that Panzer operators claim to monitor newly onboarded affiliates during their first month for possible researcher or law-enforcement activity.

Accounts showing no activity during the first week may be automatically disabled, indicating that the service is intended to maintain an active pool of operators.

Panzer Ransomware (Source: cyberxtron)
Panzer Ransomware (Source: cyberxtron)

Panzer advertises ransomware builds targeting Windows, Linux, VMware ESXi, and FreeBSD environments. This cross-platform capability creates heightened risk for enterprises operating mixed server environments, data centers, and virtualized infrastructure.

ESXi-focused ransomware attacks can cause particularly severe disruption because a compromised hypervisor may host numerous virtual machines supporting critical applications, databases, and business operations.

Criminal groups have increasingly targeted VMware infrastructure for this reason, including campaigns exploiting VMware ESXi vulnerabilities. No independently verified initial-access vector has yet been publicly attributed to Panzer.

However, activities associated with the group at medium-to-low confidence include credential dumping, brute-force attacks, network service discovery, valid account abuse, remote service lateral movement, and attempts to impair security tools.

Organizations should prioritize patching internet-facing systems, enforcing phishing-resistant multi-factor authentication, segmenting critical infrastructure, monitoring unusual outbound data transfers, and maintaining tested immutable offline backups.

No confirmed malware samples, hashes, IP addresses, or malicious domains linked to Panzer have been publicly released yet.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN



Click Here For The Original Source.

——————————————————–

..........

.

.