Lynx, also known as Lynx ransomware and LynxBlog, is a financially motivated ransomware-as-a-service operation that emerged in mid-2024. Its ransomware is closely related to the INC Ransom codebase, although the two names should not be treated as interchangeable actor identities. Lynx supplies affiliates with ransomware tooling and infrastructure and conducts double extortion by encrypting systems, exfiltrating sensitive data, and threatening publication through a dedicated leak site. Its targets include food and agriculture, healthcare, financial services, manufacturing, information technology, architecture and construction, and energy organizations. Lynx affiliates have used compromised Fortinet FortiGate and SSL VPN credentials associated with the FortiBleed campaign to obtain initial access. This relationship includes access supplied through initial access brokers; it does not establish that every upstream credential-harvesting activity was performed by Lynx itself. The Windows ransomware uses multithreaded AES file encryption and can discover and mount otherwise hidden volumes for encryption. It performs system, file, process, and network-share discovery and inhibits recovery by manipulating Volume Shadow Copy storage through DeviceIoControl. Additional extortion-related behavior includes replacing the desktop wallpaper with a ransom message and printing ransom notes through local printers. Public healthcare victim postings demonstrate that the operation's stated avoidance of hospitals is not a reliable targeting restriction.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
61 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to ransomware activity associated with the FortiBleed campaign and access to exposed FortiGate devices. The article does not separately identify Lynx's victims, geographic targets, or specific intrusion techniques.
Lynx ransomware affiliates reportedly use credentials stolen in FortiBleed attacks to obtain initial access to victim environments. The content does not specifically attribute the broader campaign's credential theft or persistence operations to Lynx.
A ransomware operation linked to the FortiBleed campaign through negotiation panels found on campaign infrastructure. The article identifies it as benefiting from compromised access, but does not establish that Lynx performed the credential-harvesting and password-cracking operation.
Ransomware operators reportedly buying network access established through the FortiBleed credential-compromise campaign. The content does not directly attribute the campaign's credential harvesting, persistence, or lateral-movement techniques to Lynx.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.