Skip to content

Security1 publisher2 min readPublished

Panzer's month-old dashboard sells ESXi ransomware builds on an 80/20 split

The RaaS operation appeared on August 5 with build management for four operating systems, Tox-gated affiliate vetting and two Italian victims, and the encryptor those affiliates are uploading still awaits public analysis.

The Watch · Security desk

Illustration accompanying Panzer's month-old dashboard sells ESXi ransomware builds on an 80/20 split

What happened

  • Panzer appeared on August 5, 2026 with a leak site and a fully featured affiliate platform, and claimed 16 to 19 victims across 11 countries in its first month.
  • Its affiliate dashboard carries build management for Windows, Linux, ESXi and FreeBSD, negotiation chat with integrated Bitcoin invoicing, and automated screening for researcher infiltration.
  • Doimo Cucine, a designer kitchen maker near Treviso, was listed on August 17, with Ransomware.live recording a claim of 30 GB of exfiltrated data.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability An affiliate who reaches a hypervisor can encrypt dozens of workloads at once, without waiting on the operator to compile anything for the target.
  • constraint Automated monitoring of new affiliates through their first month raises the price of infiltrating the platform for researchers and law enforcement.
  • exposure The population absorbing this year's Italian claims is northern manufacturing districts and technology service providers, most of them without in-house incident response.
  • precedent Early victim clusters are recruitment material for prospective affiliates, so a first-month leak site count should be read as a sales figure until samples or victim statements exist.

One ESXi build plus valid hypervisor credentials encrypts dozens of guest workloads in a single pass [17]. That is the entry on Panzer's build menu, and it is also the least verified thing about the operation. The encryptor has not been publicly analyzed [3]. What exists is an upload option in an affiliate dashboard [2], which shows what the platform sells. How its ESXi payload behaves on a live host is a separate question.

CyberXtron's September 4 profile describes a semi-open model in which prospective affiliates apply over Tox and are screened before they get dashboard access [9]. The split is 80 percent to the affiliate, 20 percent to the platform, collected automatically on each payment [10]. Seven days of inactivity deactivates an account [11]. Under the rules, CIS countries and entities involving minors are off limits [12].

Around the payment handling sit a leak publication workflow that requires team approval, countdown timers, a featured-post mechanism, a support ticketing system and sub-account management for affiliate teams [15]. Andrea Fortuna's write-up puts the model alongside VanHelsing and other recent RaaS platforms that treat affiliates as a managed workforce [16].

Italian claims stand at 212 for 2026 as of early September against 169 for all of 2025 [5], which is 43 more and about 25 percent above last year's full-year figure with the year unfinished [1]. That pace is roughly 0.85 claims a day; hold it and 2026 closes near 310, about 1.8 times 2025 [2]. Panzer is not what is driving that. It contributed two of the 212, under 1 percent [3].

Both Italian listings are attacker claims. NTE Italia, a Catanzaro firm doing telecommunications network design, project management and civil engineering consulting with offices in Rome and Catania, went up on August 21 with 16 GB of sensitive documents cited [7]. Neither it nor Doimo Cucine has publicly confirmed an incident [8]. Both match Panzer's own sector mix, technology at 25 percent of victims and manufacturing at 19 percent [14], two sectors that together account for 44 percent of a first-month list of 16 to 19 victims [4].

The practical problem for defenders is what has not been published. There are no verified malware samples and no network IOCs [4], so there is nothing to load into hash or address blocking, and detection rests on behavioral TTPs and infrastructure indicators.

What to watch

  • A published encryptor sample would let the ESXi build option be tested against what the dashboard advertises.
  • A statement from Doimo Cucine or NTE Italia, or a breach filing, would move either listing from attacker claim to confirmed incident.
  • Whether the leak site keeps posting past month one or goes quiet, as brands that front-load victims tend to.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories