Ransomware Group intelligence
Panzer
ActiveTrack Panzer with 32 published victims and 1 known leak locations in a single intelligence view.
Overview
Panzer is tracked by Breach House as a ransomware group with 32 published victims.
Indonesia is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 4h ago | pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion |
Top Activity Sectors (9)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Panzer, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Panzer executes payloads through PowerShell scripts to automate discovery, privilege escalation, and lateral movement.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Panzer executes encryption routines through Windows Service contexts to maintain persistence and evade user interaction alerts.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Panzer disables security tools by modifying Windows Defender and AV service configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Panzer encodes victim data and ransom notes using custom symmetric encryption before exfiltration to command-and-control servers.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: Panzer deletes Volume Shadow Copies and backup directories via vssadmin and built-in file deletion routines to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1564.003 Hidden Window Stealth
What they do: Panzer hides malicious processes and command execution behind hidden windows to avoid user and endpoint detection visibility.
What that means: Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
-
T1083 File and Directory Discovery Discovery
What they do: Panzer uses file and directory discovery via PowerShell to enumerate critical system and victim data paths before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Panzer moves laterally across networks by exploiting SMB/Windows Admin Shares to access additional victim machines.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: Panzer encrypts victim files using custom ransomware binaries targeting business documents and engineering assets.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Panzer inhibits system recovery by corrupting restore points and disabling backup restoration mechanisms post-encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (32)
Search, filter and paginate the victim timeline for Panzer. Showing 1–32 of 32.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Hochschule Heilbronn Bildungscampus id32562 View details | Germany | Education | ||
|
Hochschule Heilbronn Bildungscampus is a higher education institution based in Germany within the education sector, providing academic and professional training programs. The entity is cataloged in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor Panzer. This entry documents the organization's inclusion in intelligence records related to cyber incidents affecting educational infrastructure. The description remains neutral and factual, focusing solely on the entity's classification and its documented association with the specified threat actor and sector context. |
|||||
| Ransomware | Hochschule Heilbronn Bildungscampus id32562 View details | Germany | Education | ||
|
AStA Hochschule Heilbronn is the general students' committee that represents student interests both within and outside the university in Heilbronn. The organization serves as a spokesperson for the student body and provides a variety of support services, including legal and tax counseling, a grievance box, and laptop rentals. Additionally, the committee organizes numerous events and manages the university sports program. It operates as a central point of contact for students facing problems and coordinates with various student parliaments and faculty representatives. |
|||||
| Ransomware | Dinas Komunikasi dan Informatika id32447 View details | Indonesia | Telecommunications | ||
|
Dinas Komunikasi dan Informatika is Indonesia's national police and information technology security agency responsible for protecting communications infrastructure, cybersecurity operations, incident response coordination, and digital governance within the telecommunications sector. Its mandate encompasses monitoring cyber threats, supporting law enforcement and national resilience against malicious activity targeting critical information systems. This listing type identifies Dinas Komunikasi dan Informatika as a ransomware victim associated with the threat actor Panzer. The entry reflects threat-intelligence indexing findings without confirming specific breach details, data scope, or operational impact. Neutral catalog context emphasizes sector relevance, geographic origin, and the verified association with Panzer for analytical and defensive reference. |
|||||
| Ransomware | Dinas Komunikasi dan Informatika id32447 View details | Indonesia | Telecommunications | ||
|
The Central Java Province Communication and Informatics Service was formed based on Central Java Provincial Regulation Number 9 of 2016 concerning the Formation and Composition of Central Java Province Regional Apparatuses and Central Java Governor Regulation Number 70 of 2016 concerning the Organization and Work Procedure of the Central Java Province Communication and Informatics Office. As for the duties of the Central Java Province Communication and Informatics Office, it is to assist the Governor in carrying out government affairs in the communications and informatics sector, the coding sector, and the statistics sector which are the authority of the Regions and the assistance tasks assigned to the Regions. |
|||||
| Ransomware | Directorate-General for Education id32226 View details | Portugal | Education | ||
|
The Directorate-General for Education is a national education authority in Portugal responsible for overseeing policy, administration, and delivery of educational services across the country. Its work spans public education systems, curriculum coordination, institutional governance, and support for schools and educational stakeholders within the sector. This entity is cataloged as a ransomware victim associated with the threat actor Panzer, reflecting its inclusion in the threat-intelligence index based on linked incident or attribution data. The description remains factual and neutral, avoiding invented details regarding data stolen, ransom demands, breach confirmation, or operational impact. This listing supports researchers and defenders assessing education-sector exposure to coordinated cyber threats. |
|||||
| Ransomware | Directorate-General for Education id32226 View details | Portugal | Education | ||
|
The Direção-Geral de Estatísticas da Educação e Ciência (DGEEC) is a Portuguese government agency responsible for collecting, analyzing, and publishing official statistics on education, science, and technology. |
|||||
| Ransomware | Government of Vojvodina id32077 View details | Serbia | Public Sector | ||
|
The Government of Vojvodina is a regional government entity within Serbia (RS), operating in the Public Sector. It administers regional governance functions, public services, infrastructure planning, and policy implementation across the Vojvodina region of Serbia. As a Public Sector organization, it handles administrative, regulatory, and service delivery responsibilities for its jurisdiction. This listing identifies the Government of Vojvodina as a ransomware victim associated with the threat actor Panzer. The entry reflects its inclusion in the threat-intelligence index based on this association, presented neutrally without confirming specific breach details. |
|||||
| Ransomware | Government of Vojvodina id32077 View details | Serbia | Public Sector | ||
|
The Provincial Government of Vojvodina is focused on enhancing economic and academic cooperation within the region and internationally. SENVIBE project is to improve and build national educational capacities, cooperation and competences in dealing with environmental and occupational noise and vibration (No&Vib) engineering issues in accordance with ongoing EU integration strategies and the needs identified in Serbia. |
|||||
| Ransomware | Senvibe id32066 View details | United States | IT | ||
|
Senvibe operates within the information technology sector and maintains infrastructure serving enterprise and professional clients. As an IT entity located in the United States, Senvibe provides technology-focused solutions and services relevant to digital operations and system management. This listing identifies Senvibe as a ransomware victim associated with the threat actor Panzer. The entry reflects threat-intelligence indexing data concerning this entity and its connection to the specified adversary. No additional breach details, such as data stolen or ransom demands, are included per strict factual constraints. |
|||||
| Ransomware | Senvibe id32066 View details | United States | IT | ||
|
SENVIBE project is to improve and build national educational capacities, cooperation and competences in dealing with environmental and occupational noise and vibration (No&Vib) engineering issues in accordance with ongoing EU integration strategies and the needs identified in Serbia. |
|||||
| Ransomware | Nteitalia id31961 View details | Italy | — | ||
|
NTE Italia, an engineering and telecommunications service provider based in Catanzaro, Italy. Sensitive thousands of documents are compromised. |
|||||
| Ransomware | Frisian Flag Indonesia id31838 View details | Indonesia | — | ||
|
Frisian Flag Indonesia specializes in high-quality dairy products, including sweetened condensed milk, UHT milk, powdered milk for families, and cheese. The company aims to provide nutritious options that support the health and well-being of families, offering products enriched with vitamins and minerals. Their target clients include families, pregnant women, and children, focusing on delivering nutritional benefits through their diverse product range. Established in 1871, Frisian Flag is committed to building strong families by promoting healthy dietary habits. |
|||||
| Ransomware | DL E&C id31796 View details | Korea, Republic of | — | ||
|
DL E&C Co., Ltd. is a major South Korean construction and engineering company, founded in 1939, specializing in building, infrastructure, housing, and industrial/energy plant projects worldwide. |
|||||
| Ransomware | Castilla La Mancha id31788 View details | Spain | — | ||
|
The Government of Castilla-La Mancha provides a wide range of services and information related to public administration, economy, education, health, and social services. It aims to support various sectors including agriculture, tourism, and employment, while also addressing issues like sustainability and equality. The intended clients include residents of Castilla-La Mancha, businesses, and individuals seeking assistance in various life situations. The government also promotes transparency and participation through its digital platforms. |
|||||
| Ransomware | Doimo Cucine id31787 View details | Italy | — | ||
|
Doimo Cucine specializes in modern, customizable designer kitchens that blend beauty and harmony. The company emphasizes a holistic approach to kitchen design, offering a versatile system called All-arounD for creating personalized spaces. With a commitment to quality and innovation, all production is carried out in Italy, ensuring high standards and craftsmanship. Their target clients are those seeking stylish and functional kitchen solutions that nourish the soul. |
|||||
| Ransomware | SAGASTA sro id31776 View details | Czechia | Other | ||
|
SAGASTA sro is a company based in the Czech Republic, operating in the other sector. The company's specific offerings are not well-documented, but it is known to be a part of the Czech business landscape. SAGASTA sro was listed as a ransomware victim associated with Panzer. |
|||||
| Ransomware | SAGASTA sro id31776 View details | Czechia | Other | ||
|
SAGASTA is a design and engineering company specializing in modern construction, offering comprehensive design, engineering, and consulting services in the fields of railway, road, bridge, and water management construction. |
|||||
| Ransomware | Infosat id31751 View details | Telecommunications | |||
|
Infosat operates in the telecommunications sector, providing various services to its customers. As a company in this sector, Infosat likely offers a range of telecommunications solutions. Infosat was listed as a ransomware victim associated with Panzer |
|||||
| Ransomware | Infosat id31751 View details | Telecommunications | |||
|
A company focused on new technologies serving information, communications and security systems.It was created at the dawn of the third millennium, with the primary mission of serving its clients and committing to its partners for overall and sustainable performance. |
|||||
| Ransomware | Alpine Electronics Europe id31723 View details | Germany | Manufacturing / Engineering | ||
|
Alpine Electronics Europe operates in the manufacturing and engineering sector, offering various products and services in Germany. As a subsidiary of the global Alpine Electronics group, the company is involved in the development and production of electronic components. Alpine Electronics Europe was listed as a ransomware victim associated with Panzer. |
|||||
| Ransomware | Alpine Electronics Europe id31723 View details | Germany | Manufacturing / Engineering | ||
|
Alpine Electronics Europe specializes in the distribution of automotive electronics and audio products. The company offers a range of products and support services tailored for various European markets. Their intended clients include automotive manufacturers and consumers seeking high-quality audio solutions. Alpine is committed to providing innovative technology and exceptional customer service across multiple countries in Europe. |
|||||
| Ransomware | Xpress Tech id31573 View details | IT | |||
|
Xpress Tech is an IT sector company, though specific details about its location and offerings are not readily available. As an entity within the IT sector, it likely provides various technology-related services and solutions. Xpress Tech was listed as a ransomware victim associated with Panzer. |
|||||
| Ransomware | Xpress Tech id31573 View details | IT | |||
|
Xpress Tech is a leading B2B iGaming aggregation platform established in 2015 under Softquo Holding. It provides a comprehensive one-stop technical solution connecting operators with over 120 gaming providers and a portfolio of more than 30,000 games via a single Remote API integration. The platform also features integrated payment solutions and back-office data management |
|||||
| Ransomware | The Minor Food Group id31529 View details | Thailand | Hospitality / Food & Beverage / Tourism | ||
|
Founded in 1980, Minor Food is the culinary pillar of Minor International (MINT) and one of the largest food and beverage companies in the Asia-Pacific region. With a footprint spanning over 2,600 outlets across 24 countries, Minor Food operates a dynamic dual-engine strategy combining globally renowned franchises—such as Burger King, Dairy Queen, Swensen's, and Bonchon—with a powerful roster of wholly-owned homegrown brands like The Pizza Company, The Coffee Club, and GAGA. Committed to delivering exceptional dining experiences, Minor Food continues to drive the industry forward through digitized kitchen ecosystems, end-to-end supply chain mastery, and consumer-centric innovation. |
|||||
| Ransomware | Siam Oil Product id31484 View details | Thailand | Energy | ||
|
Siam Oil Product is an energy company based in Thailand, operating in the oil sector. The company likely provides various oil products to meet the energy demands of the region. Siam Oil Product was listed as a ransomware victim associated with Panzer |
|||||
| Ransomware | Siam Oil Product id31484 View details | Thailand | Energy | ||
|
Siam Oil Product Co., Ltd. is a Thailand-based petroleum and industrial-products distributor, operating for 20+ years with registered capital of THB 200 million and 700+ employees; it supplies fuel oil, diesel, asphalt, base oils, automotive/industrial lubricants, petrochemicals such as HDPE/LDPE/LLDPE, plastic additives, and industrial products, and also operates a coffee-shop franchise business. Its headquarters is at RS Tower, Ratchadaphisek Road, Din Daeng, Bangkok, Thailand. |
|||||
| Ransomware | Daily Trust id31483 View details | Nigeria | Communication / Marketing | ||
|
Daily Trust is a Nigerian media and marketing company operating in the communication sector. The company provides various marketing and media services in Nigeria. Daily Trust was listed as a ransomware victim associated with Panzer. |
|||||
| Ransomware | Daily Trust id31483 View details | Nigeria | Communication / Marketing | ||
|
Daily Trust is a Nigerian news organization that provides breaking news, investigative stories, and various features across multiple sectors including business, politics, sports, and entertainment. The company offers content through print, online platforms, and media outlets like Trust TV and Trust Radio. Its services cater primarily to the Nigerian public, with a focus on providing comprehensive coverage of local and international news. Daily Trust aims to inform and engage its audience through a diverse range of storytelling and analysis. |
|||||
| Ransomware | Surakarta University id31348 View details | Indonesia | Education | ||
|
Ums.ac.id is a website associated with the Universitas Muhammadiyah Surakarta, a university in Indonesia that provides higher education services. The university offers various academic programs and is located in the city of Surakarta, Central Java, Indonesia. Ums.ac.id was listed as a ransomware victim associated with Panzer |
|||||
| Ransomware | Surakarta University id31348 View details | Indonesia | Education | ||
|
Universitas Surakarta (UNSA) is a technology-based university committed to excellence in education, business, and entrepreneurship, responsive to industry and community needs. It offers a range of programs including undergraduate, professional conversion, and postgraduate studies, aimed at developing competent and character-driven graduates. UNSA provides a flexible and collaborative learning environment, supported by experienced faculty and modern infrastructure. The university invites prospective students, partners, and the community to join in building a brighter and more meaningful future together. |
|||||
| Ransomware | Festina Group id31349 View details | Switzerland | Manufacturing / Engineering | ||
|
Festina Group is a company based in Switzerland, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Festina Group was listed as a ransomware victim associated with Panzer |
|||||
| Ransomware | Festina Group id31349 View details | Switzerland | Manufacturing / Engineering | ||
|
Festina Group is a major watch and jewelry company that owns six different brands: Festina, Lotus, Lotus Style, Calypso, Candino, and Jaguar. They blend Swiss watchmaking traditions with modern design, creating timepieces that mix classic craftsmanship with contemporary style. Each brand offers something unique, from sporty watches to elegant jewelry, giving customers plenty of choices for different tastes and occasions. |
|||||