Galago is a newly identified ransomware operation first flagged by researchers on. The group claims an operational partnership with the established Panzer ransomware group, supported by a shared naming convention across both groups' leak site infrastructure. Galago's own Dark Leak Site (DLS) was found inactive/down at the time of observation, with no victims published. Galago operates using mechanisms that include packers and crypters to deliver its payload.
The threat uses sandbox or VM checks to evade defense systems. Persistence is achieved through privilege escalation, allowing it to maintain a foothold on compromised systems. Galago communicates through network protocols, but specific details are not provided in the article. The group collects sensitive information from compromised devices and stores it encrypted.[/subscribe_to_unlock_form]
Galago is a newly identified ransomware operation first flagged by researchers on. The group claims an operational partnership with the established Panzer ransomware group, supported by a shared naming convention across both groups' leak site infrastructure. Galago's own Dark Leak Site (DLS) was found inactive/down at the time of observation, with no victims published. Galago operates using mechanisms that include packers and crypters to deliver its payload.
The threat uses sandbox or VM checks to evade defense systems. Persistence is achieved through privilege escalation, allowing it to maintain a foothold on compromised systems. Galago communicates through network protocols, but specific details are not provided in the article. The group collects sensitive information from compromised devices and stores it encrypted.[emaillocker id="1283"]
The significance of Galago's operation lies in its emerging partnership with Panzer, which has published 32 victims between and. This suggests a coordinated effort to conduct double-extortion attacks. Defensive implications include the need for continuous patching and identity verification across remote access services and unmanaged infrastructure.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Exfiltration | T1567.002 | Exfiltration Over Web Service | Exfiltration to Cloud Storage |
| Impact | T1486 | Data Encrypted for Impact | - |
The following reports contain further technical details:
[/emaillocker]