Panzer Ransomware Targets Italian Firms with ESXi-Ready RaaS
Key Takeaways Panzer ransomware, a new RaaS operation, emerged on August 5, 2026, and is actively targeting Italian organizations. The group advertises ransomware variants for Windows, Linux,...
Key Takeaways
- Panzer ransomware, a new RaaS operation, emerged on August 5, 2026, and is actively targeting Italian organizations.
- The group advertises ransomware variants for Windows, Linux, FreeBSD, and critically, VMware ESXi systems.
- Initial alleged victims include an Italian kitchen manufacturer and a telecommunications engineering firm, with claims of data exfiltration.
- The rise of Panzer coincides with a significant increase in ransomware attacks in Italy, surpassing previous annual totals.
- Panzer operates a structured RaaS model, offering affiliates tools and a dashboard for managing attacks and negotiations.
A new ransomware-as-a-service (RaaS) operation dubbed Panzer has recently emerged, specifically setting its sights on Italian enterprises amidst a notable surge in cyberattacks across the nation. Since its initial appearance on August 5, 2026, Panzer has already claimed several victims, including a kitchen manufacturer in Treviso and a telecommunications engineering firm in Catanzaro, Italy.
The group distinguishes itself by providing affiliates with a diverse toolkit capable of targeting a range of operating systems, including Windows, Linux, FreeBSD, and critically, VMware ESXi. The ability to compromise virtualization hosts like ESXi is particularly concerning, as a single successful attack can incapacitate numerous business applications simultaneously, leading to widespread operational disruption from a solitary compromised server.
Panzer has listed victims across 11 countries, with its Italian campaign unfolding as the country experiences an escalating ransomware threat. By September 6, 2026, Italy had already reported 212 alleged ransomware incidents, surpassing the total of 169 recorded throughout all of 2025. This alarming trend highlights the increasing vulnerability of Italian organizations to such attacks. A detailed report on Panzer’s activities, including its targeting of Italian firms, is available here.
Researcher Andrea Fortuna said in a report shared with Cyber Security News (CSN) that claims of victims by Panzer should be approached with caution. Neither Doimo Cucine nor NTE Italia had publicly confirmed the incidents at the time of the report’s publication, suggesting that these listings might be a tactic to establish credibility for the nascent ransomware group.
Panzer Ransomware Targets Italian Manufacturers
The Panzer operation is notable not for a publicly scrutinized encryptor, but for its sophisticated business infrastructure. Prospective affiliates undergo a screening process via Tox, after which they gain access to a comprehensive dashboard. This platform facilitates various aspects of their illicit activities, including generating ransomware builds, managing negotiations with victims, issuing payment invoices, posting leaked data, and administering team accounts.
The RaaS model employed by Panzer outlines an 80/20 split, with affiliates retaining 80 percent of each ransom payment and the platform taking the remaining 20 percent. Operators reportedly implement rigorous monitoring of new affiliates to detect any signs of infiltration by researchers or law enforcement, underscoring a tightly controlled recruitment process. Further details on this operational structure can be found in the report.
The ESXi capability of Panzer poses a severe threat to manufacturing and telecommunications firms that heavily rely on virtual machines for their critical operations. If an attacker gains control of a hypervisor, they can encrypt multiple virtual disks, bringing down numerous dependent services instead of being limited to a single endpoint. Prior analysis of <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a47c4dab-53a8-425d-9418-f897713877cd/Panzer-Ransomware-Targets-Italian-Manufacturers-and-Telecom-Firms-With-ESXi-Ready-RaaS.pdf?AWSAccessKeyId=ASIA2F3EMEYE2IOQLHWM&Signature=MWnkD4LQGbBC13yAnS1C1JAy%2Bso%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEIn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDF3ZBYB2gC0oy%2B8D%2BxeB88Zj0doEqg%2BOQMFbxWUUAm2gIhAIgeU%2Bri0QUAvmdy2JENKTeslBRzv
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.