Brazil: Panzer and Play list new victims
Panzer claimed K3G Solutions and Play claimed Metallco. Unit 42 also reported a phishing campaign against Brazil's financial sector.
The Panzer ransomware group listed Brazilian telecom and IT consultancy K3G Solutions, based in Manaus, on its leak site. In parallel, Play listed Metallco, a Brazilian manufacturing company, as a victim. Unit 42 also reported, via The Hacker News, on a campaign against Brazil's financial sector using resume-themed phishing emails, custom RATs and tunneling tools.
Panzer listed K3G Solutions, a Brazilian telecom and IT consultancy based in Manaus, on its leak site. At the same time, Play posted Metallco, a Brazilian manufacturing company, as a victim on its own site. In parallel, a Unit 42 report cited by The Hacker News described a campaign against Brazil's financial sector that used resume-themed phishing emails, custom RATs and tunneling tools.
What is known about the K3G Solutions case?
K3G Solutions Brazil appears in records from several trackers, but with different levels of confidence. Kalir Pulse included it among the victims posted by Panzer, while Recent Breaches treated it as an unverified claim and said it found no public confirmation from the company, no data types and no number of affected people.
Ransomware.live went further in its case file and attributed an estimated 300 GB of exfiltrated data, along with four compromised employees, 31 compromised users and four third-party employee credentials. Breach House, meanwhile, added K3G Solutions Brazil to its Brazil incident register as a Panzer claim and described it as a Brazilian telecom and IT consultancy based in Manaus.
What did Unit 42 say about the campaign in Brazil?
Unit 42, according to The Hacker News, detected a campaign identified as CL-CRI-1163 that targeted Brazil's financial sector with resume-based phishing emails to deploy custom RATs and tunneling tools. The cited material also mentioned a Go-based SOCKS5 proxy.
The Unit 42-linked findings add that initial access came through a resume-themed email attachment. The page identified in the search also pointed to attempts to install SockTz versions 1 through 8 from a compromised WordPress site. Unit 42 interpreted the iterative naming pattern in the Go-based SOCKS5 proxy as a possible sign of AI assistance in development.
What other cases appeared in Brazil?
Kalir Pulse also reported that Play listed Metallco as a victim on its leak site. The company is Brazilian and operates in manufacturing.
Taken together, the material includes two ransomware cases with Brazilian victims published on leak sites and an additional technical report that broadens the focus on campaigns aimed at organizations in the country, in this case with emphasis on the financial sector and deception tactics tied to resumes.
Sources
- Victim: K3G Solutions Brazil – Panzerransomware.live· Ransomware.liveUnverified URL
- Ransomware Panzer publica a la consultora brasileña K3G Solutionspulse.kalir.io· Kalir Pulse
- Ransomware Play publica a la fabricante brasileña Metallcopulse.kalir.io· Kalir Pulse
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Storiesthehackernews.com· The Hacker News
- K3G Solutions Brazil Ransomware Claim (2026) — What’s Alleged & Am I Affected?recentbreaches.com· Recent Breaches
- K3G Solutions Brazil — PANZER Ransomware Attackbreach.house· Breach House
- Unit 42 search result for CL-CRI-1163unit42.paloaltonetworks.com· Palo Alto Networks Unit 42
- Unit 42 search result referencing SockTz and CL-CRI-1163unit42.paloaltonetworks.com· Palo Alto Networks Unit 42



