Threat Advisory

Galago Ransomware Claims Operational Partnership with Panzer

Threat: Malware
Threat Actor Name: Galago
Threat Actor Type: Financially Motivated
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Galago is a newly identified ransomware operation first flagged by researchers on. The group claims an operational partnership with the established Panzer ransomware group, supported by a shared naming convention across both groups' leak site infrastructure. Galago's own Dark Leak Site (DLS) was found inactive/down at the time of observation, with no victims published. Galago operates using mechanisms that include packers and crypters to deliver its payload.

The threat uses sandbox or VM checks to evade defense systems. Persistence is achieved through privilege escalation, allowing it to maintain a foothold on compromised systems. Galago communicates through network protocols, but specific details are not provided in the article. The group collects sensitive information from compromised devices and stores it encrypted.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Galago is a newly identified ransomware operation first flagged by researchers on. The group claims an operational partnership with the established Panzer ransomware group, supported by a shared naming convention across both groups' leak site infrastructure. Galago's own Dark Leak Site (DLS) was found inactive/down at the time of observation, with no victims published. Galago operates using mechanisms that include packers and crypters to deliver its payload.

The threat uses sandbox or VM checks to evade defense systems. Persistence is achieved through privilege escalation, allowing it to maintain a foothold on compromised systems. Galago communicates through network protocols, but specific details are not provided in the article. The group collects sensitive information from compromised devices and stores it encrypted.[emaillocker id="1283"]

The significance of Galago's operation lies in its emerging partnership with Panzer, which has published 32 victims between and. This suggests a coordinated effort to conduct double-extortion attacks. Defensive implications include the need for continuous patching and identity verification across remote access services and unmanaged infrastructure.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Exfiltration T1567.002 Exfiltration Over Web Service Exfiltration to Cloud Storage
Impact T1486 Data Encrypted for Impact -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu