Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

panzer Ransomware Group

Ransomware group profile

46Victims
RussiaSource country
80Impact score

Description

Panzer is a financially motivated ransomware group that emerged in August 2026, known for its rapid targeting of high-profile international organizations. The group utilizes a double-extortion model, threatening to release sensitive data if ransom demands are not met, and features a dedicated TOR leak site for operational communications and victim pressure.

Key insights

  • Employs custom file-encrypting malware and appends extortion-related tags to files.
  • Exfiltrates confidential corporate documents and sensitive customer records for leverage.
  • Targets various sectors including education, energy, manufacturing, and retail.
  • Operates a dark web leak site to facilitate extortion and recruit affiliates.
  • Shows rapid operational deployment with a focus on high-profile targets.

Threat Level & Status Breakdown

For panzer · Based on incidents in selected period

3.7threat level
Aggressiveness10/ 10
Lethality0/ 10
Criticality0.7/ 10

Status Breakdown

Claimed100.0%46
First seenAug 2026
Last seenSep 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedSep 17, 2026

Recent activity

Monthly attack count for panzer in the selected period

46Total attacks
29peak in Sep
23avg / month
↑ 12 vs first month
AugSep08162432

Intelligence

IOCs, YARA/Sigma rules, and related families for panzer

  1. pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion
  2. ixxrzs3zo57qhbscszen2nvx6hgav5zrx6tjs7lq6unsphwcadeadlid.onion
  3. 34enzhp4pkfrj5bnmede23wk2io2a44nj23ldwvv3stkaewurup7svad.onion
  4. qxstd6r6zkzgoolpdqsdxf4lq6rhukgpngwrgbejyyioqy2kwbkxpiyd.onion
  5. tvhm7xw756yscfixmoyr2aymgu4oan66ospp44vcykvgxmgyq3ua2vyd.onion
  6. uchhaxue34fz6r2nyrvatxynponoe7wy6ffhwwigpfbz5zgz24w5b6id.onion
View full IOC feed6 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for panzer

Credential Access

T1003

OS Credential Dumping

T1110

Brute Force

Defense Evasion

T1562

Impair Defenses

Discovery

T1046

Network Service Discovery

Execution

T1059

Command and Scripting Interpreter

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(46)

FranceTechnologystim.fr
Claimed
about 12 hours ago
BrazilTechnologyinovapy.com
Claimed
about 12 hours ago
GermanyEducationuni-hamburg.de
Claimed
about 12 hours ago
GermanyOthernielsen-design.de
Claimed
2 days ago
PeruManufacturinghonda.com.pe
Claimed
3 days ago
PeruManufacturingceramicaskantu.com
Claimed
5 days ago
Government & Defense
Claimed
7 days ago
Government & Defense
Claimed
7 days ago
Government & Defense
Claimed
7 days ago
Government & Defense
Claimed
7 days ago
Government & Defense
Claimed
7 days ago
Government & Defense
Claimed
7 days ago
BulgariaManufacturingkonicaminolta.bg
Claimed
7 days ago
SpainGovernment & Defenseaemet.es
Claimed
7 days ago
Claimed
8 days ago
PortugalOtheraqualogus.com
Claimed
9 days ago
Government & Defense
Claimed
9 days ago
Government & Defense
Claimed
9 days ago
Government & Defense
Claimed
9 days ago

Page 1 of 3