Panzer, a ransomware-as-a-service (RaaS) operation, has expanded its reach into Italy, naming a kitchen manufacturer in Treviso and a telecommunications engineering firm in Catanzaro among its targets. The criminal network went public with these alleged attacks on August 5. Panzer advertises tools for Windows, Linux, FreeBSD, and critically, VMware ESXi environments—meaning it can potentially cripple multiple virtualized services in one strike.
This move comes amidst a sharp surge in ransomware cases in Italy. By September 6, victims tally reached 212, significantly higher than the 169 incidents recorded during all of 2025. Though the Treviso manufacturer Doimo Cucine and Catanzaro’s NTE Italia are listed among Panzer’s victims, neither organization has publicly confirmed the breach. Some cybersecurity experts view those listings as part of Panzer’s credibility strategy.
How Panzer’s RaaS Operates
Panzer is structured like many other RaaS groups: it recruits affiliates via secure messaging, screens applicants, and grants access to dashboards for planning attacks, negotiating payments, issuing invoices, and posting stolen data. The profit split is reportedly 80% for affiliates, 20% for the core operators. Vetting is enforced to weed out researchers or law enforcement.
A key capability is its VMware ESXi option. Organizations using virtualized infrastructures—including many manufacturers and telecom providers—are at risk: a compromised hypervisor could lead to data encryption across all virtual machines, not just individual endpoints. Reports on ESXi attacks corroborate that virtualization control is a growing vector for large-scale ransomware deployment.
Data Theft, Initial Access & Attack Paths
Alongside data encryption, Panzer claims to have exfiltrated 30 GB from Doimo Cucine and 16 GB from NTE Italia. Such theft can force organizations into double-extortion scenarios even when backups allow system recovery. While the precise payload and full access method haven’t been detailed, analysts believe Panzer’s tactics likely include credential theft, remote-service abuse, phishing, and exploitation of internet-facing tools.
Possible breach vectors are exposed VPN or gateway devices, exposed Remote Desktop Protocol services, phishing campaigns, and remote management software vulnerabilities. Weak or reused credentials, unpatched systems, and oversight of external-facing appliances are recurring vulnerabilities.
Mitigation & Best Practices for Virtual Environments
Organizations affected—or at risk—should enforce phishing-resistant multi-factor authentication (MFA) for all remote access points, especially VPNs and privileged accounts. Privilege minimization, credential rotation, and prompt patching of internet-exposed devices and remote management tools are essential.
Network segmentation is critical. Hypervisors, domain controllers, backup systems, and virtual management interfaces must be isolated from general user networks. Administrative protocols should be restricted to monitored segments to prevent lateral movement from compromises.
Watch for early warning signs: unusual VPN logins, new admin accounts, remote tool abuse, large-scale archive creation, and suspicious cloud transfer utilities. Commands that disable system recovery tools (like “vssadmin delete shadows” or “bcdedit recoveryenabled no”) are red flags.
Maintain immutable or offline backups across all environments—not just endpoints. Regularly test recovery plans, especially for interconnected virtual workloads. Also, build legal and communications strategies now to be ready for double extortion scenarios.
Here are two Indicators of Compromise tied to Panzer: the leak site address pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion, and a Tox ID used in affiliate recruitment.
Panzer’s rise puts a spotlight on how ransomware operations are increasingly targeting virtual infrastructure and leveraging RaaS models that reduce technical barriers to entry. For Italian manufacturers and telecom firms—and their global counterparts—securing ESXi environments and tightening remote access protocols isn’t optional anymore. Vigilance, layered defenses, and robust response planning will make all the difference.