Back to Intelligence

PANZER Ransomware Gang: 4 New Leak-Site Listings Across Education, Manufacturing & Professional Services — Sector Analysis & Detection Rules

SA
Security Arsenal Team
October 7, 2026
14 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-08 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

PANZER Ransomware Gang: 4 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules

Executive Summary

Security Arsenal's dark web monitoring of the PANZER ransomware operation's .onion leak site, aggregated via ransomware.live, shows 4 new victim listings published between 2026-10-02 and 2026-10-07. The listings span four sectors — Education, Manufacturing, Professional Services, and an uncategorized "Other" — and three countries: Germany, the United States, and Brazil.

Critical caveat up front: every entry below is a claim made by a criminal group on its own extortion infrastructure. A leak-site posting is an accusation, not a confirmed breach. None of the organizations named below have, to our knowledge, publicly confirmed an incident, and this briefing does not assert that any breach occurred. What is confirmed is that PANZER is actively publishing, actively targeting mid-market organizations across three continents, and worth preparing for regardless of whether any single listing proves accurate.

Named listings:

OrganizationSectorCountryPublishedCorroboration
University of RostockEducationDE2026-10-07Multi-source (two crawlers observed the posting)
EDFelectronicsManufacturingUnknown2026-10-06Multi-source
SweetRushProfessional ServicesUS2026-10-06Multi-source
PaessolucoesOtherBR2026-10-02Single-source (ransomware.live only)

Sourcing & Verification

  • Corroboration status: 3 of the 4 listings above were independently observed by a second leak-site crawler, confirming that PANZER did publish those claims. 1 listing (Paessolucoes) appears on ransomware.live only, with no second-crawler confirmation that the posting even exists. Treat that entry with additional skepticism — single-source dark web data is sometimes stale, rescraped, or erroneous.
  • What corroboration means — and does not mean: Multi-source confirmation establishes that the gang made the claim. It does not confirm that a breach, intrusion, or data theft occurred at any named organization. No corroboration tier in our data confirms a breach; only the affected organization or its regulator can do that.
  • Denials and silence are also inconclusive: A named organization may dispute a listing, and a denial is not proof the claim is false — disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question either way.
  • Corrections: Security Arsenal will publish corrections to this briefing as warranted. We welcome contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — PANZER

PANZER is a comparatively low-volume entrant in the ransomware extortion ecosystem. Public reporting on the group remains thin, so the profile below blends confirmed leak-site telemetry with assessed-typical behaviors for groups of its size and tempo. Where we are inferring rather than observing, we say so.

  • Aliases: No widely documented aliases or rebrands have been attributed to PANZER in public reporting to date. Low-volume groups of this profile frequently rebrand or operate as spin-offs of larger RaaS programs; we assess it is possible PANZER shares lineage with a larger operation, but we have no evidence confirming that.
  • Operating model: Posting cadence (4 listings over ~6 days) is consistent with either a small closed crew or a young RaaS program with few active affiliates. We currently lean toward emerging RaaS or small closed group, but attribution of the affiliate structure is unconfirmed.
  • Ransom demands: No public ransom amounts for PANZER are documented. Groups targeting mid-market organizations in these sectors typically demand in the low-to-mid six figures USD, scaled to victim revenue — treat this as sector-typical context, not a PANZER-specific figure.
  • Initial access methods: Unconfirmed for PANZER specifically. Groups of this class most commonly gain entry via (1) exploitation of internet-facing remote access services (VPN appliances, RDP), (2) phishing with macro- or script-based payloads, and (3) purchased access from initial access brokers. Harden against all three.
  • Extortion model: The existence of a leak site with named listings indicates a double-extortion approach — data theft threatened alongside encryption. Defenders should assume exfiltration precedes detonation.
  • Dwell time: Unknown for PANZER. Industry-wide, median dwell time for ransomware intrusions has compressed to roughly 3–7 days, with many groups staging and exfiltrating within 72 hours of initial access. Plan detection around a short fuse.

Current Campaign Analysis

Sector targeting. The current posting batch touches Education, Manufacturing, Professional Services, and one uncategorized entity. This is a classic opportunistic mid-market spread rather than a focused vertical campaign — groups at this maturity stage typically publish whatever their access yields. That said, the education listing (University of Rostock, claim) fits a well-established pattern: universities remain attractive because of open network architectures, seasonal access churn, research data with resale/extortion value, and historically understaffed security teams. Manufacturing and professional services listings fit the standard ransomware economics of operational downtime pressure and client-confidential data.

Geographic concentration. DE, US, BR — no concentration. This scatter supports the opportunistic-access hypothesis rather than a regionally focused crew. Brazil's appearance is consistent with the broader 2025–2026 trend of ransomware groups expanding Latin American targeting as North American and European defenses harden.

Victim profile. Based on the sectors named, the claimed victims appear to sit in the small-to-mid-market band (estimated tens to low hundreds of millions USD annual revenue/budget for the private-sector entities; the university is a large public institution). Groups at PANZER's volume typically avoid headline-grabbing critical infrastructure and instead target organizations large enough to pay but small enough to lack 24/7 SOC coverage.

Posting frequency and escalation. 4 listings in 6 days (2026-10-02 through 2026-10-07), with 3 of 4 posted in a 48-hour window (10-06 through 10-07). Batch posting like this often indicates either (a) a queue of negotiated-then-failed extortions released at once, or (b) a deliberate publicity push to establish the brand. Watch for whether cadence sustains over the next 2–3 weeks; sustained cadence would suggest an active affiliate pipeline.

CVE exposure — hypothesis only. We have no evidence linking any specific CVE to any specific listing above. However, the currently active CISA KEV entries most relevant to the intrusion vectors this class of actor favors are worth treating as priority patch items regardless of PANZER attribution:

  • CVE-2026-50751 (Check Point Security Gateway, improper authentication in IKEv1) — perimeter VPN exploitation is the single most common initial access path for groups of this profile.
  • CVE-2026-20316 (Cisco Secure FMC, hard-coded password) — network management plane compromise enables both initial access and defense evasion.
  • CVE-2026-59310 (VMware vCenter path traversal) — vCenter compromise is a force multiplier for mass encryption of virtualized estates.
  • CVE-2026-63077 (JetBrains TeamCity deserialization) — CI/CD compromise enables supply-chain-style lateral spread and credential harvesting.
  • CVE-2026-48027 (Nx Console embedded malicious code) — developer-toolchain compromise; relevant to professional services and software-adjacent victims.

Again: these are sector-level exposure hypotheses. No named organization above should read this as an assertion about how any alleged intrusion occurred.

Detection Engineering

The following detections target the TTP cluster typical of double-extortion crews at PANZER's profile: RDP/VPN initial access, PsExec/WMI lateral movement, pre-encryption data staging, and shadow copy destruction. They are platform-agnostic by design — tune thresholds to your baseline.

YAML
---
title: RDP Brute Force Followed by Successful Logon - Potential Ransomware Initial Access
id: 8f3a2c10-panz-4e01-b001-rdpbrute0001
status: experimental
description: Detects a burst of failed RDP logons (Event 4625, logon type 3/10) from a single source followed by a successful logon (4624 type 3/10) to the same host within 10 minutes. Consistent with ransomware crew initial access via exposed RDP.
author: Security Arsenal Threat Intel
logsource:
  product: windows
  service: security
detection:
  selection_failed:
    EventID: 4625
    LogonType:
      - 3
      - 10
  selection_success:
    EventID: 4624
    LogonType:
      - 3
      - 10
  condition: selection_failed | count() by IpAddress, TargetComputer > 20
  timeframe: 10m
level: high
tags:
  - attack.initial_access
  - attack.t1133
  - attack.t1110
date: 2026/10/08
---
title: PsExec or Remote Service Creation for Lateral Movement
id: 8f3a2c10-panz-4e02-b002-psexec000002
status: experimental
description: Detects service creation events indicative of PsExec-style lateral movement (services with random 16-char names, ADMIN$ writes, or psexesvc) commonly used by ransomware operators for mass deployment pre-encryption.
author: Security Arsenal Threat Intel
logsource:
  product: windows
  service: system
detection:
  selection_svc:
    EventID: 7045
  filter_known_psexec:
    ServiceName|contains:
      - 'PSEXESVC'
      - 'psexec'
  selection_random_name:
    ServiceName|re: '^[A-Za-z0-9]{16}$'
  selection_admin_path:
    ImagePath|contains:
      - 'ADMIN$'
      - '\\.\\pipe\\'
  condition: selection_svc and (filter_known_psexec or selection_random_name or selection_admin_path)
level: high
tags:
  - attack.lateral_movement
  - attack.t1021.002
  - attack.t1569.002
date: 2026/10/08
---
title: Pre-Encryption Staging - Shadow Copy Deletion and Archive Creation
id: 8f3a2c10-panz-4e03-b003-staging00003
status: experimental
description: Detects the pre-detonation sequence common to double-extortion ransomware - volume shadow copy deletion (vssadmin/wmic/ bcdedit) and mass archive creation (rar/7z) within a short window, indicating exfil staging and anti-recovery actions.
author: Security Arsenal Threat Intel
logsource:
  category: process_creation
  product: windows
detection:
  selection_shadow:
    CommandLine|contains:
      - 'vssadmin delete shadows'
      - 'vssadmin.exe Delete Shadows'
      - 'shadowcopy delete'
      - 'bcdedit'  # paired with recoveryenabled no
      - 'wbadmin delete catalog'
  selection_archive:
    Image|endswith:
      - '\rar.exe'
      - '\7z.exe'
      - '\7za.exe'
      - '\winrar.exe'
    CommandLine|contains:
      - ' a -r'
      - ' a -m'
  condition: selection_shadow or selection_archive
level: critical
tags:
  - attack.impact
  - attack.t1490
  - attack.t1560.001
  - attack.exfiltration
date: 2026/10/08

The following Sentinel hunt query looks for the lateral-movement and staging pattern typical of ransomware crews in the 72-hour pre-detonation window: an identity authenticating to an unusual number of hosts, combined with remote execution tooling and archive/utility process execution on servers.

KQL — Microsoft Sentinel / Defender
// PANZER-class ransomware pre-detonation hunt: lateral movement + staging
// Looks for identities touching many hosts AND executing staging/lateral tooling
let lookback = 7d;
let staging_procs = dynamic(["psexec.exe","psexesvc.exe","rar.exe","7z.exe","7za.exe","winrar.exe","wmic.exe","vssadmin.exe","bcdedit.exe","nltest.exe","adfind.exe","netscan.exe","softperfect_network_scanner.exe"]);
let suspicious_logons =
    SecurityEvent
    | where TimeGenerated > ago(lookback)
    | where EventID == 4624 and LogonType in (3, 10)
    | where Account !startswith "NT AUTHORITY" and Account !endswith "$"
    | summarize DistinctTargets = dcount(Computer), Targets = make_set(Computer, 50) by Account, SourceIP = IpAddress
    | where DistinctTargets >= 8;
let staging_exec =
    SecurityEvent
    | where TimeGenerated > ago(lookback)
    | where EventID == 4688
    | where Process has_any (staging_procs) or CommandLine has_any ("delete shadows","recoveryenabled no","\\ADMIN$\\")
    | summarize StagingEvents = count(), Tools = make_set(Process, 20), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
        by Account = SubjectAccount, Computer;
staging_exec
| join kind=inner suspicious_logons on Account
| project Account, Computer, StagingEvents, Tools, FirstSeen, LastSeen, DistinctTargets, SourceIP
| order by DistinctTargets desc, StagingEvents desc

The following PowerShell script is a rapid-response sweep: it enumerates RDP exposure, scheduled tasks created in the last 7 days (a common persistence/staging vector), recent shadow copy tampering, and new local admin additions. Run it domain-wide via your EDR or PS remoting when a PANZER-style listing mentions your sector.

PowerShell
# PANZER Rapid-Response Sweep - run as Domain Admin via PS Remoting or EDR live response
# Checks: RDP exposure, new scheduled tasks (7d), shadow copy status, new local admins

$ErrorActionPreference = 'SilentlyContinue'
$report = [ordered]@{}

# 1. Is RDP enabled and exposed?
$rdpEnabled = (Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server').fDenyTSConnections -eq 0
$rdpNLA     = (Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp').UserAuthentication
$report['RDP_Enabled']      = $rdpEnabled
$report['RDP_NLA_Enforced'] = ($rdpNLA -eq 1)
if ($rdpEnabled -and $rdpNLA -ne 1) {
    Write-Warning 'RDP enabled WITHOUT Network Level Authentication - high-risk exposure.'
}

# 2. Scheduled tasks created or modified in the last 7 days (persistence/staging)
$cutoff = (Get-Date).AddDays(-7)
$newTasks = Get-ScheduledTask | ForEach-Object {
    $info = $_ | Get-ScheduledTaskInfo
    [PSCustomObject]@{
        TaskName   = $_.TaskName
        TaskPath   = $_.TaskPath
        Author     = $_.Author
        LastRun    = $info.LastRunTime
        Action     = ($_.Actions | ForEach-Object { "$($_.Execute) $($_.Arguments)" }) -join ' | '
    }
} | Where-Object { $_.Author -notmatch 'Microsoft' -and $_.TaskPath -notmatch '^\\Microsoft' }
$report['NonMicrosoft_Tasks'] = $newTasks
if ($newTasks) {
    Write-Warning "$($newTasks.Count) non-Microsoft scheduled tasks found - review Action fields for script/binary staging."
    $newTasks | Format-Table -AutoSize | Out-String | Write-Host
}

# 3. Volume Shadow Copy status - ransomware anti-recovery check
$shadows = Get-CimInstance Win32_ShadowCopy
$report['ShadowCopies_Present'] = [bool]$shadows
if (-not $shadows) {
    Write-Warning 'NO volume shadow copies present. Either VSS is disabled by policy or shadow copies were deleted (T1490). Check Event IDs for vssadmin/wmic execution.'
}
$vssEvents = Get-WinEvent -FilterHashtable @{LogName='Application'; ProviderName='VSS'; StartTime=$cutoff}
$report['VSS_Events_7d'] = $vssEvents.Count

# 4. Local administrators - unexpected additions are a lateral-movement red flag
$admins = Get-LocalGroupMember -Group 'Administrators' | Select-Object Name, ObjectClass, PrincipalSource
$report['Local_Admins'] = $admins
$admins | Format-Table -AutoSize | Out-String | Write-Host

# 5. Recent 4625 burst check - brute force indicator (last 24h)
$failed = Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)}
$report['FailedLogons_24h'] = $failed.Count
if ($failed.Count -gt 200) {
    Write-Warning "$($failed.Count) failed logons in 24h - investigate for brute force (T1110)."
}

$report | ConvertTo-Json -Depth 4 | Out-File "$env:TEMP\panzer_sweep_$(Get-Date -Format yyyyMMdd_HHmm).json"
Write-Host "Sweep complete. Report written to $env:TEMP" -ForegroundColor Green

Incident Response Priorities

If your organization appears on PANZER's leak site — or your sector does — the following reflects the typical double-extortion playbook for groups of this class:

T-minus detection checklist (before encryption fires):

  • New or anomalous VPN/RDP authentications, especially outside business hours or from unusual geographies/ASNs, followed by internal logon-type-3 fan-out.
  • Execution of reconnaissance tooling: nltest, AdFind, netscan, BloodHound/SharpHound artifacts (*.json/*.csv collections in temp directories).
  • Mass archive creation (rar.exe, 7z.exe) on file servers, databases, or executive workstations — this is your exfiltration staging signal and usually your last pre-detonation warning.
  • Outbound transfers to cloud storage (MEGA, Rclone configs, file.io) or sustained multi-gigabyte egress from a single host.
  • vssadmin delete shadows, bcdedit ... recoveryenabled no, wbadmin delete catalog — if you see this, detonation is imminent; move directly to containment.

Assets this class of actor typically prioritizes for exfiltration:

  • HR records and payroll/PII (highest regulatory pressure on victims).
  • Financial records, contracts, and legal correspondence (direct extortion leverage).
  • Client/customer data — particularly acute for professional services firms, whose listing puts their clients at downstream risk.
  • For education targets: research data, student records, and donor information.
  • Backup catalogs and credentials (to maximize destructive impact and negotiating leverage).

Containment actions, ordered by urgency:

  1. Isolate, don't power off. Network-isolate suspected hosts at the switch/EDR level. Preserve volatile memory for forensics; shutdowns destroy evidence and can trigger dead-man detonation scripts.
  2. Disable the suspected compromised identity enterprise-wide and force credential resets for anything it touched — assume Kerberos ticket theft, not just password compromise.
  3. Block egress to known staging destinations (Rclone endpoints, MEGA, paste/transfer services) at the proxy/firewall immediately.
  4. Protect backups now. Verify backup immutability/offline status and rotate backup infrastructure credentials before touching anything else — backup destruction typically precedes encryption.
  5. Snapshot the perimeter. Audit VPN, RDP, and remote management exposure; disable any account or appliance you cannot immediately account for.
  6. Engage counsel and IR retainer early. Extortion deadlines are a pressure tactic; decisions about communication, negotiation, and disclosure should not be made ad hoc at hour 36.
  7. Do not confirm or deny publicly on the gang's timeline. Leak-site listings are designed to force panicked statements. Coordinate external communications with counsel.

Hardening Recommendations

Immediate (24 hours):

  • Patch or mitigate the perimeter KEV entries above, prioritizing CVE-2026-50751 (Check Point) and CVE-2026-20316 (Cisco FMC) — perimeter device exploitation is the highest-probability initial access vector for this actor class. If patching isn't possible inside 24h, restrict management interfaces to allow-listed admin hosts.
  • Enforce MFA on all remote access (VPN, RDP gateways, VDI) with no service-account exceptions. Audit for legacy IKEv1 configurations specifically.
  • Block or alert on vssadmin delete shadows, bcdedit recovery tampering, and non-admin execution of rar.exe/7z.exe on servers — deploy the Sigma rules above.
  • Verify backup immutability and test one restore. Offline or object-locked backups are the single highest-leverage control against double extortion.
  • Sweep with the PowerShell script above on your highest-value servers: file servers, domain controllers, backup infrastructure.

Short-term (2 weeks):

  • Eliminate direct internet RDP entirely. Move all administrative access behind a VPN plus jump host with just-in-time elevation. RDP should never answer on 3389 from the internet.
  • Segment by blast radius. Isolate backup networks, management planes (vCenter, FMC, CI/CD), and user workstations into separate security zones with deny-by-default east-west rules. CVE-2026-59310 (vCenter) and CVE-2026-63077 (TeamCity) are only catastrophic if a perimeter foothold can reach them.
  • Deploy egress filtering and DLP alerting on bulk outbound transfers and unsanctioned cloud storage — exfiltration is the extortion leverage; if you can see it and stop it, the gang's threat collapses.
  • Deploy honeycred/canary accounts with interactive logon alerting. Ransomware operators almost universally enumerate and touch privileged accounts during recon.
  • Establish a leak-site monitoring watch for your organization, your subsidiaries, and (for professional services firms) your largest clients — a listing naming your client may be your first warning of your own exposure.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.