Panzer: Galago Ransomware Emerges With Shared Infrastructure Ties to Panzer

Panzer: Galago Ransomware Emerges With Shared Infrastructure Ties to Panzer

Galago Ransomware Emerges with Alleged Ties to Panzer Group

A newly identified ransomware operation, Galago, has surfaced with claims of collaboration with the Panzer ransomware group, though evidence remains circumstantial. Researchers first detected Galago on 9 September 2026 following an open-source alert alleging an attack on an Icelandic healthcare organization, Inter ehf, with a reported theft of 105 GB of data. The group’s dark leak site (DLS), monitored from 15 September, was inactive at the time of observation, with no confirmed victims listed.

Galago’s Tor leak-site address (pnzr4delgur5dlhtqcy7qqm6m7dkivxwh742enezpks5kswfpx7qrsid[.]onion) shares a pnzr prefix with Panzer’s (pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion), suggesting a potential naming link. However, this alone does not confirm shared operators, malware, or infrastructure. Galago’s self-reported partnership with Panzer remains unverified, and no independent evidence supports the alleged Icelandic breach.

Panzer, in contrast, has a more established track record, with 32 victims published between 5 August and 23 September 2026. Described as a ransomware-as-a-service (RaaS) operation, Panzer recruits affiliates and employs double extortion, encrypting files while exfiltrating data. Its advertised capabilities include builds for Windows, Linux, ESXi, and FreeBSD, though these should not be attributed to Galago without further proof.

The 9 September report claiming Galago’s compromise of Inter ehf included a threat to publish stolen data by 28–29 September, but this remains unsubstantiated. Neither Galago’s leak site nor independent verification has confirmed the breach. Defenders are advised to monitor the provided Tox contact ID (8C3D96497A7A9438794F705C055FC2FD3059F6CF11FF51060EE55ED7F0679CFC7218825BD56CB1) and Tor addresses for further activity, though these identifiers alone do not prove network compromise.

As of now, Galago’s operational status and its alleged connection to Panzer remain unconfirmed, with no independently verified malware samples or attack infrastructure linked to either group.

Source: https://cyberpress.org/galago-ransomware-linked-to-panzer/

E-Panzer cybersecurity rating report: https://www.rankiteo.com/company/epanzersecurity

"id": "EPA1790239953",
"linkid": "epanzersecurity",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Healthcare',
                        'location': 'Iceland',
                        'name': 'Inter ehf',
                        'type': 'Healthcare Organization'}],
 'data_breach': {'data_exfiltration': '105 GB (alleged)',
                 'sensitivity_of_data': 'High (healthcare data)'},
 'date_detected': '2026-09-09',
 'date_publicly_disclosed': '2026-09-15',
 'description': 'A newly identified ransomware operation, Galago, has surfaced '
                'with claims of collaboration with the Panzer ransomware '
                'group, though evidence remains circumstantial. Researchers '
                'first detected Galago on 9 September 2026 following an '
                'open-source alert alleging an attack on an Icelandic '
                'healthcare organization, Inter ehf, with a reported theft of '
                '105 GB of data. The group’s dark leak site (DLS) was '
                'monitored from 15 September but was inactive at the time of '
                'observation, with no confirmed victims listed. Galago’s Tor '
                'leak-site address shares a prefix with Panzer’s, suggesting a '
                'potential naming link, but this does not confirm shared '
                'operators, malware, or infrastructure. Galago’s self-reported '
                'partnership with Panzer remains unverified, and no '
                'independent evidence supports the alleged Icelandic breach.',
 'impact': {'data_compromised': '105 GB (alleged)'},
 'investigation_status': 'Unconfirmed',
 'motivation': 'Financial gain (extortion)',
 'ransomware': {'data_exfiltration': '105 GB (alleged)',
                'ransomware_strain': 'Galago'},
 'recommendations': 'Monitor Tox contact ID and Tor addresses for further '
                    'activity. Verify claims independently before attributing '
                    'attacks to Galago or Panzer.',
 'references': [{'date_accessed': '2026-09-15',
                 'source': 'Dark Leak Site (DLS)',
                 'url': 'http://pnzr4delgur5dlhtqcy7qqm6m7dkivxwh742enezpks5kswfpx7qrsid.onion'}],
 'threat_actor': ['Galago', 'Panzer (alleged)'],
 'title': 'Galago Ransomware Emerges with Alleged Ties to Panzer Group',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.