Lynx is a financially motivated ransomware-as-a-service operation that emerged in mid-2024 and is widely assessed as an evolution or rebrand of INC Ransom, with substantial code overlap reported between the two malware families and shared affiliate ecosystem links. Known aliases include lynxblog and lynx_ransomware. The operation uses double extortion, combining file encryption with data exfiltration and publication pressure through leak-site and negotiation infrastructure. Victim communications are conducted through authenticated portals and dedicated contact channels, and the group has maintained an active leak-blog presence since 2024. Lynx has targeted organizations globally, with reporting tying activity to victims in the United States, the United Kingdom, Germany, Australia, and elsewhere. Sectors directly associated with Lynx victimization include health care, financial services, manufacturing, energy, construction and architecture, information technology manufacturing, real estate and business services, and government or emergency-services entities. Reporting also links a shared affiliate between Lynx and the FortiBleed access ecosystem, indicating downstream use of compromised perimeter infrastructure for ransomware deployment. The malware and operations associated with Lynx support core ransomware lifecycle behaviors including initial access through affiliates, persistence, exfiltration, defense evasion, and impact via encryption. Technical reporting describes AES-based multithreaded encryption, hidden-drive discovery and mounting, deletion of shadow-copy data through low-level device control rather than common administrative utilities, desktop-wallpaper modification, ransom-note printing to local printers, and host and network discovery behaviors aligned with ATT&CK techniques such as system, process, file, and network-share enumeration. Public reporting also characterizes Lynx as part of a broader affiliate ecosystem with overlaps to historical RaaS operations including Nemty, Nemty X, Karma, and Nokoyawa. Separate reporting observed an affiliate previously linked to the Lynx and INC ecosystems deploying DeadLock ransomware, reinforcing the role of Lynx as an affiliate-driven criminal ecosystem rather than a single closed operator set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
38 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation maintaining leak sites, negotiation portals, chat/registration infrastructure, ransom notes, and victim communication channels to support extortion campaigns.
Referenced as a ransomware ecosystem linked to an affiliate observed deploying DeadLock.
Referenced as a ransomware ecosystem previously linked to an affiliate deploying DeadLock.
Named as a ransomware affiliate/group materially connected to DeadLock deployment activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.