Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

panzer Ransomware Group

Ransomware group profile

53Victims
RussiaSource country
80Impact score

Description

Panzer is a financially motivated ransomware group that emerged in August 2026, known for its rapid targeting of high-profile international organizations. The group utilizes a double-extortion model, threatening to release sensitive data if ransom demands are not met, and features a dedicated TOR leak site for operational communications and victim pressure.

Key insights

  • •Employs custom file-encrypting malware and appends extortion-related tags to files.
  • •Exfiltrates confidential corporate documents and sensitive customer records for leverage.
  • •Targets various sectors including education, energy, manufacturing, and retail.
  • •Operates a dark web leak site to facilitate extortion and recruit affiliates.
  • •Shows rapid operational deployment with a focus on high-profile targets.

Threat Level & Status Breakdown

For panzer · Based on incidents in selected period

3.1threat level
Aggressiveness8/ 10
Lethality0/ 10
Criticality0.9/ 10

Status Breakdown

Claimed100.0%53
First seenAug 2026
Last seenOct 2026
Avg ransom—
Payment rate—
Statusactive
Sophistication0
Last updatedOct 7, 2026

Recent activity

Monthly attack count for panzer in the selected period

53Total attacks
33peak in Sep
17.7avg / month
↓ 14 vs first month
AugSepOct09182736

Intelligence

IOCs, YARA/Sigma rules, and related families for panzer

  1. pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion
  2. ixxrzs3zo57qhbscszen2nvx6hgav5zrx6tjs7lq6unsphwcadeadlid.onion
  3. 34enzhp4pkfrj5bnmede23wk2io2a44nj23ldwvv3stkaewurup7svad.onion
  4. qxstd6r6zkzgoolpdqsdxf4lq6rhukgpngwrgbejyyioqy2kwbkxpiyd.onion
  5. tvhm7xw756yscfixmoyr2aymgu4oan66ospp44vcykvgxmgyq3ua2vyd.onion
  6. uchhaxue34fz6r2nyrvatxynponoe7wy6ffhwwigpfbz5zgz24w5b6id.onion
  7. pnzr4delgur5dlhtqcy7qqm6m7dkivxwh742enezpks5kswfpx7qrsid.onion
View full IOC feed7 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for panzer

Credential Access

T1003

OS Credential Dumping

T1110

Brute Force

Defense Evasion

T1562

Impair Defenses

Discovery

T1046

Network Service Discovery

Execution

T1059

Command and Scripting Interpreter

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(53)

PolandManufacturing
Claimed
about 6 hours ago
United StatesProfessional Services
Claimed
about 11 hours ago
BrazilOtherpaessolucoes.com.br
Claimed
4 days ago
United KingdomHealthcaresmcare.co.uk
Claimed
9 days ago
FranceProfessional Servicesressources-si.com
Claimed
9 days ago
SpainProfessional Servicesasesoriafar.com
Claimed
9 days ago
BrazilOtherk3gsolutions.com.br
Claimed
18 days ago
FranceTechnologystim.fr
Claimed
19 days ago
BrazilTechnologyinovapy.com
Claimed
19 days ago
GermanyEducationuni-hamburg.de
Claimed
19 days ago
GermanyOthernielsen-design.de
Claimed
21 days ago
PeruManufacturinghonda.com.pe
Claimed
22 days ago
PeruManufacturingceramicaskantu.com
Claimed
23 days ago
Government & Defense
Claimed
26 days ago
Government & Defense
Claimed
26 days ago
Government & Defense
Claimed
26 days ago
Government & Defense
Claimed
26 days ago
Government & Defense
Claimed
26 days ago
Government & Defense
Claimed
26 days ago

Page 1 of 3