New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group
Galago ransomware, linked to Panzer, allegedly stole 105 GB from Icelandic healthcare firm Inter ehf; its leak site is inactive.
A new ransomware brand called Galago publicly claims a partnership with the Panzer extortion group. Its Tor leak site, monitored from 15 September 2026, was inactive and listed no victims, but the domain uses the same pnzr prefix as Panzer's site. Panzer published 32 alleged victims between 5 August and 23 September 2026. An unconfirmed 9 September report alleged Galago took about 105 GB from Icelandic healthcare organization Inter ehf, with a possible publication window around 28-29 September; no encryption or data publication has been independently verified.
- Galago's leak-site domain uses the same pnzr prefix as Panzer.
- Galago claims a Panzer partnership; its leak site was inactive with no listings.
- Panzer published 32 alleged victims from 5 August to 23 September 2026.
- Unconfirmed claim of about 105 GB taken from Icelandic healthcare firm Inter ehf.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | pnzr4delgur5dlhtqcy7qqm6m7dkivxwh742enezpks5kswfpx7qrsid.onion | warrant close monitoring. IOCs Type Value Galago DLS (Tor) pnzr4delgur5dlhtqcy7qqm6m7dkivxwh742enezpks5kswfpx7qrsid[.]onion — currently down/inactive Panzer DLS (Tor) pnzruro7syvwve |
| domain | pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion | px7qrsid[.]onion — currently down/inactive Panzer DLS (Tor) pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion Panzer Tox ID 8C3D96497A9438794F705C055FC2FD3059F6CF11FF5 |
Full article684 words · extracted from gbhackers.com · click to collapse
A newly identified ransomware operation tracked as Galago has emerged with apparent operational links to the Panzer ransomware group, raising concerns of an expanding double-extortion ecosystem targeting organizations worldwide.
Researchers began directly monitoring Galago’s dark leak site (DLS) on 15 September 2026. At the time of observation, the group’s Tor-based leak portal was inactive and contained no published victim entries.
While this limits independent verification of the operation’s claims, the infrastructure associated with the site indicates a possible relationship with the more established Panzer extortion operation.
Galago publicly states that it operates in partnership with Panzer.
The claim is supported by a shared naming pattern across the groups’ leak-site infrastructure: Galago’s domain begins with the pnzr prefix, a naming convention also used in Panzer’s own leak-site address.
Although shared infrastructure alone does not prove full organizational integration, it is a notable technical indicator that both operations may be collaborating, sharing hosting resources, or operating within the same affiliate ecosystem.

Cyberxtron Researchers said that, Galago group was first observed on 9 September 2026 after an open-source alert alleged that Galago had compromised an Iceland-based healthcare organization.
Galago Ransomware Operation
Panzer has maintained an active double-extortion campaign in recent months. Between 5 August and 23 September 2026, the group published 32 alleged victims on its data-leak site, demonstrating sustained operational activity.
This cadence suggests that Panzer may provide infrastructure, access-broker relationships, operational support, or extortion capabilities to emerging brands such as Galago.
The apparent launch of Galago may represent a deliberate rebranding or expansion strategy rather than a fully independent ransomware group.
Threat actors frequently establish new brands to segment campaigns, evade reputation-based detection, test new victim-facing infrastructure, or continue operations after increased scrutiny of an existing ransomware name.
The pnzr naming overlap makes Panzer a key lead for defenders investigating Galago-related intrusions.

The only known Galago-associated victim claim involves Inter ehf, an Iceland-based hospitals and healthcare organization.
On 9 September, an external report alleged that Galago had compromised approximately 105 GB of data from the organization.
The attackers reportedly indicated that the data would be published within 19 to 20 days, placing the anticipated leak window around 28 or 29 September.
However, the alleged Inter ehf compromise remains unconfirmed. The claim predates direct monitoring of Galago’s DLS, and the group has not published a corresponding victim listing.
No independently verified evidence of network access, encrypted systems, stolen files, or data publication has been observed.
Organizations should therefore treat the incident as an allegation until corroborated by the victim, the leak site, or additional technical reporting.
The healthcare sector remains a particularly high-impact target for ransomware operators due to the potential for operational disruption, sensitive patient data exposure, and urgent recovery requirements.
If confirmed, the Inter ehf case would align Galago with a broader trend of extortion groups targeting organizations that hold high-value personal, medical, financial, and operational data.
Security teams should monitor for Panzer- and Galago-related infrastructure indicators, including newly registered or Tor-hosted resources using the pnzr naming convention.
Incident responders should also review logs for suspicious credential access, unusual remote administration activity, large outbound data transfers, and the use of common dual-use tools that may facilitate data theft before encryption.
At present, Galago’s operational maturity remains unclear. Its inactive leak site and absence of published victims suggest the group may still be establishing infrastructure or preparing for an initial public extortion campaign.
Nevertheless, the claimed partnership and naming correlation with Panzer warrant close monitoring.
IOCs
| Type | Value |
| Galago DLS (Tor) | pnzr4delgur5dlhtqcy7qqm6m7dkivxwh742enezpks5kswfpx7qrsid[.]onion — currently down/inactive |
| Panzer DLS (Tor) | pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion |
| Panzer Tox ID | 8C3D96497A9438794F705C055FC2FD3059F6CF11FF51060EE55ED7F0679CFC7218825BD56CB1 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.