Panzer ransomware targets Windows, Linux, and VMware ESXi servers
A new ransomware called Panzer can lock up Windows, Linux, and VMware ESXi servers. Attackers use it to encrypt files and demand payment to unlock them.
- Report priority
- High
- Victim
- Windows
- Group
- Panzer
What is known
- Attackers send a malicious file or link to a server.
- When opened, the file encrypts important files and replaces them with a ransom note.
- The note demands payment in cryptocurrency to get the files back.
- This works on Windows, Linux, VMware ESXi, and FreeBSD systems.
What to do
Check if your servers were targeted by looking for encrypted files with unusual extensions like '. Panzer' or '.locked'. If you see a ransom note asking for Bitcoin, your system is affected. Also, review recent emails or downloads for suspicious attachments or links.
Do not pay the ransom. Instead, disconnect the infected server from the network immediately. Contact your IT team or a cybersecurity professional to restore files from backups. Update your antivirus software and monitor for further signs of infection. Report the incident to your organization's security team or authorities if needed.
Reported details
Attackers send phishing emails with malicious attachments or links to target servers. Once clicked, the file encrypts files on Windows, Linux, or VMware ESXi systems, then displays a ransom note demanding payment in Bitcoin.
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments.