Overview
A new ransomware‑as‑a‑service (RaaS) operation called Panzer has surfaced in Italy, targeting manufacturers and telecom firms with an ESXi‑ready encryptor. First observed on August 5, 2026, Panzer listed victims including a kitchen manufacturer in Treviso and a telecommunications engineering firm in Catanzaro. The campaign coincides with a surge in ransomware incidents in Italy, which reached 212 cases by September 6, surpassing the 169 recorded in all of 2025.
Panzer’s RaaS Model
- Affiliate recruitment: Prospective affiliates apply via Tox, undergo screening, and gain access to a dashboard for builds, negotiations, payments, and leak posts.
- Revenue split: Affiliates receive 80% of ransom payments, while operators retain 20%.
- Controlled onboarding: Operators monitor affiliates to detect researchers or law enforcement infiltration.
Technical Threats
- ESXi targeting: Attacks on VMware ESXi hypervisors can encrypt multiple virtual disks, halting dependent services across entire organizations.
- Data theft: Panzer claimed 30 GB stolen from Doimo Cucine and 16 GB from NTE Italia.
- Possible entry routes: Vulnerable VPNs, exposed RDP services, phishing emails, and abused remote‑management tools.
- Associated tactics: Password attacks, credential theft, local data collection, security tool tampering, and data transfers via alternative protocols.
Indicators of Compromise (IoCs)
- Leak site (.onion):
pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion - Tox ID (affiliate recruitment):
8C3D96497A9438794F705C055FC2FD3059F6CF11FF51060EE55ED7F0679CFC7218825BD56CB1 - Dashboard mapping: Exploits CVE‑2026‑59310 and other major VMware ESXi vulnerabilities from 2025–2026.
Defensive Guidance
Italian organizations should:
- Enforce phishing‑resistant MFA for VPNs, remote administration, and privileged accounts.
- Patch internet‑facing appliances and conduct regular exposure reviews.
- Segment critical systems: Isolate domain controllers, backup repositories, vCenter, and ESXi interfaces from user networks.
- Monitor warning signs: Unusual VPN logins, new admin accounts, PsExec/WMI activity, large archives, or unfamiliar cloud‑transfer utilities.
- Respond to critical commands: Unexpected
vssadmin delete shadowsorbcdedit recoveryenabled noshould trigger immediate incident response. - Maintain offline backups and test restorations routinely.
- Prepare for double extortion: Monitor outbound transfers, and have legal and communications plans ready.
Expert in the Cloud Insight
Panzer’s arrival underscores the evolution of ransomware into enterprise‑grade operations. By targeting ESXi hypervisors, attackers maximize disruption, encrypting workloads that underpin manufacturing and telecom services. The lesson is clear: virtualization infrastructure must be defended with the same rigor as endpoints, combining segmentation, telemetry, and immutable backups to withstand modern RaaS campaigns.
Leave a Reply