Galago is an emerging purported ransomware operation first identified in September 2026. Its operators claim a partnership with the Panzer ransomware group, but no evidence establishes shared operators, tooling, victim access, malware, or intrusion procedures. Galago’s public leak infrastructure was inactive during monitoring, and no intrusion, ransomware payload, initial-access method, or victim has been independently verified. The operation has alleged that it compromised Icelandic healthcare organization Inter ehf and stole data, but the alleged compromise, theft, and any resulting disruption remain unconfirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Emerging ransomware/extortion operation with an unverified claimed partnership with Panzer. Its intrusion vector, payload, victims, and operational impact remain unconfirmed; the only named victim allegation concerns Inter ehf in Iceland.
An emerging ransomware/extortion operation with an unverified claimed partnership with Panzer. Its only specific alleged victim is Icelandic healthcare organization Inter ehf; neither the claimed 105 GB data theft nor a resulting disruption has been independently verified.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.