The recently emerged Panzer ransomware-as-a-service operation has claimed Italian kitchen manufacturer Doimo Cucine and telecommunications engineering firm NTE Italia among victims reportedly spanning 11 countries. Panzer says it pairs encryption with data theft, alleging it stole 30 GB from Doimo Cucine and 16 GB from NTE Italia; neither company had publicly confirmed an incident. The group advertises payloads for Windows, Linux, FreeBSD, and VMware ESXi, placing virtualized environments at risk of broad, simultaneous service disruption.
Researchers have not independently verified Panzer’s initial-access vector or analyzed its encryptor. Limited-confidence assessments associate the operation with credential attacks, remote-service abuse, security-tool tampering, data collection, and exfiltration through alternative protocols. Organizations should prioritize phishing-resistant MFA, patch exposed remote-access services, segment vCenter and ESXi management networks, monitor for pre-encryption activity, and maintain tested immutable or offline backups.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Panzer listed Italian kitchen manufacturer Doimo Cucine and telecommunications engineering firm NTE Italia on its victim site, claiming theft of 30 GB and 16 GB of data respectively. Neither organization had publicly confirmed a ransomware incident at the time of reporting.
The Panzer ransomware-as-a-service operation surfaced and began advertising tooling for Windows, Linux, FreeBSD, and VMware ESXi environments.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.