A newly identified ransomware operation calling itself Galago has claimed a partnership with the Panzer ransomware group and alleged theft of 105 GB of data from Icelandic healthcare organization Inter ehf. CyberXTron identified the group in September 2026 and began monitoring its Tor leak site, which was inactive and contained no published victim listings.
Neither the alleged Inter ehf intrusion and data theft nor any operational disruption has been independently verified. Researchers have not observed a Galago payload, initial-access method, confirmed victim disclosure, or technical evidence tying the group to an affected environment; the asserted Panzer connection rests on self-description and similar leak-site naming conventions, not verified shared operators or tooling. Healthcare organizations, particularly in the Nordic region, should reinforce phishing-resistant MFA, remote-access controls, tested backups, monitoring for unusually large outbound transfers, and data-breach response plans.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
CyberXTron began monitoring Galago's Tor leak site on September 15 and found it inactive with no victims published. The site claimed a partnership with Panzer, but similar leak-site naming prefixes and the self-described relationship did not verify shared operators, tooling, or victim access.
On September 9, CyberXTron identified the emerging Galago ransomware operation following an open-source alert alleging an attack on Icelandic healthcare organization Inter ehf. Galago allegedly claimed it stole 105 GB of Inter ehf data, but the intrusion, theft, and any resulting disruption were not independently verified.
CyberXTron recorded 32 victim postings on Panzer's leak site between August 5 and September 23, characterizing Panzer's visible activity as double extortion. These postings do not independently verify the alleged compromises or establish a connection to Galago.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
cyberaccord.com
Open sourcecybersecuritynews.com
Open sourcecyberxtron.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.