LIVE
LATEST THREAT: China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware THREAT ALERT ACTIVE
Intelligence DB / Group Profile Panzer

Panzer: New RaaS Operation Rapidly Expands Global Victim List

Panzer, a newly emerged ransomware-as-a-service operation, has posted victims across Europe, Asia, and Africa within weeks of its leak site going live, including an Italian engineering firm listed August 21, 2026. The group is actively recruiting affiliates with an 80/20 revenue split and a cross-platform locker.

By Ransomware Tracker ·
PanzerransomwareRaaSdouble extortionemerging groupleak siteaffiliate recruitment2026
Threat Level
8/10
Sectors Targeted
energy
manufacturing
media
retail
education
technology
Ransomware Family
Panzer

Overview

Panzer is a newly surfaced ransomware-as-a-service operation whose dark web leak site began publishing victims in mid-2026, with activity accelerating sharply through July and August. Trackers including RansomLook and ransomware.live have logged a growing list of confirmed postings, and independent threat-intel outlets flagged Panzer as a distinct new entrant to the RaaS landscape rather than a rebrand of an existing brand. As with any group in its first weeks of public activity, elements of Panzer’s self-description — recruitment terms, technical claims — remain unverified and should be treated with appropriate caution, but the leak site postings and associated victim disclosures are independently corroborated across multiple monitoring services.

Panzer operates a standard double-extortion model: data is exfiltrated prior to encryption, and the leak site is used to pressure non-paying victims with the threat of publication. Analysts tracking the group’s onion portal describe an aggressive naming-and-shaming cadence, with the operation sometimes releasing small proof-of-exfiltration file samples quickly after an intrusion to increase pressure during the negotiation window.

Rapid, Cross-Regional Victim Spread

What distinguishes Panzer from many newly launched groups is the geographic and sectoral spread of its victim list within a short window. Confirmed leak-site postings tracked by open-source researchers include:

  • NTE Italia, an Italian engineering and telecommunications services provider, listed August 21, 2026
  • Siam Oil Product, an energy and utilities company in Thailand
  • Daily Trust, a media organization in Nigeria
  • Festina Group, a watchmaking and jewelry company
  • Doimo Cucine, an Italian kitchen manufacturer
  • DL E&C, a South Korean engineering and construction firm
  • The Minor Food Group and Xpress Tech, both posted with claimed data exfiltration
  • Surakarta University, an Indonesian academic institution

The breadth of sectors — energy, media, manufacturing, food service, education, and construction — and the spread across Southeast Asia, West Africa, Europe, and South Korea in a matter of weeks suggests either a sizeable affiliate roster active from launch or a small core team deliberately targeting opportunistically across regions to build leak-site volume quickly. Both patterns are common early-stage strategies for RaaS operators trying to establish credibility with prospective affiliates: a fast-growing, geographically diverse victim list functions as a marketing signal on cybercrime forums.

Affiliate Recruitment

Open-source reporting on Panzer’s recruitment activity describes the group advertising for penetration testers and other affiliates on underground forums, offering access to a management platform and a claimed multi-platform locker. The revenue split reported is 80% to the affiliate and 20% retained by the operators, deducted automatically from each payment — the industry-standard split used by most active RaaS brands, including LockBit-lineage and Conti-derivative operations.

Reported recruitment rules include prohibitions on targeting organizations in CIS countries (a near-universal rule among Russian-speaking-adjacent RaaS operations, generally understood as an effort to avoid domestic law enforcement attention), a ban on targeting entities involved in child exploitation, and removal of affiliates who go inactive for more than a week. Applications are reportedly handled through a Tox-based support channel, a common out-of-band communication method used by ransomware operators to avoid platform moderation on forums.

These recruitment terms are self-reported by the group and have not been independently validated through infiltration or leaked internal communications, unlike some rival groups whose internal structures have been exposed through inter-criminal conflicts. They should be read as Panzer’s public pitch to prospective affiliates rather than confirmed operational fact.

Technical Profile

Public technical analysis of Panzer’s encryptor remains limited given the group’s short public track record. Reporting describes a multi-platform locker capability, consistent with the broader RaaS trend toward Windows, Linux, and ESXi support to maximize the value of a single intrusion — encrypting the hypervisor layer affects every guest VM simultaneously, a technique popularized by Qilin and Akira and now close to standard practice among active RaaS families.

Initial access in documented cases has reportedly involved phishing and exploitation of exposed remote services, consistent with the low-cost, high-volume access-broker model that supplies most mid-tier RaaS affiliates today.

Assessment

Panzer’s trajectory over the next few months will indicate whether it consolidates into a durable mid-tier RaaS brand or fades as many short-lived operations do. Factors worth monitoring include whether the group sustains its current posting pace, whether affiliate quality improves (larger, better-defended targets rather than opportunistic SMB hits), and whether law enforcement or rival-group disclosures expose more of its internal infrastructure — a pattern that has provided the clearest intelligence on comparable newly launched groups like KryBit.

Defensive Priorities

Given the group’s apparent reliance on phishing and exposed remote services for initial access, organizations should prioritize: enforcing MFA on all remote access and VPN services, monitoring for anomalous authentication from unfamiliar geographies, restricting internet exposure of management interfaces (particularly for virtualization platforms), and maintaining offline, tested backups given the group’s double-extortion model. Because Panzer is new and its leak site content changes rapidly, organizations in the energy, manufacturing, media, and education sectors — where confirmed victims have already appeared — should treat threat intelligence on this group as provisional and monitor trusted trackers for updates.

Sources

// Related Intelligence
Group Profile

Titan Ransomware: A New RaaS Group Behind a Nine-Victim, Single-Day Strike on Italian Firms

Group Profile

Gunra Ransomware: Conti-Derived RaaS Expands to Five Continents with Multi-Sector Targeting

Group Profile

Stormous: Pro-Russian Hacktivist Group That Evolved Into Financially Motivated Ransomware