Panzer emerged in August as a ransomware-as-a-service operation and, within its first month, was claiming victims in 11 countries, according to researcher Andrea Fortuna. Two of the listed targets were Italian firms: Doimo Cucine, a kitchen manufacturer, and NTE Italia, a telecommunications engineering and consulting company, though neither claim has been publicly confirmed.
The notable part is Panzer’s affiliate platform, which includes builds for Windows, Linux, VMware ESXi, and FreeBSD plus negotiation, payment, and leak-site tools. ESXi matters because a hit on the hypervisor can encrypt the guest virtual machines it hosts and the services running on them, so one compromise can take out more than a single server.
For VMware ESXi operators, especially in manufacturing and telecom, that shifts the blast radius to shared infrastructure: if the host goes down, the workloads on top of it can disappear together. The reporting does not yet settle how Panzer gets in, but it does show the group building for fleet-scale extortion rather than isolated intrusions.