Lynx is a ransomware family and ransomware-as-a-service operation that emerged in mid-2024. It shares substantial code with INC Ransom, although code overlap does not establish that the operations are identical. Lynx provides affiliates with ransomware tooling and supporting infrastructure and uses double extortion, combining file encryption with data theft and threats to publish stolen information on a Tor-based leak site. Its targets span multiple regions and include finance, manufacturing, architecture, construction, and energy organizations.
The Windows encryptor uses multithreaded AES encryption and can discover and mount otherwise unmounted volumes to expand its encryption scope. It inhibits recovery by manipulating Volume Shadow Copy storage through DeviceIoControl rather than relying on standard shadow-copy administration utilities. It selectively excludes files and directories, decodes an embedded Base64 ransom note, changes the desktop wallpaper to display ransom demands, and can print ransom notes on local printers. Its behavior also includes file, system, network-share, and process discovery.
Lynx affiliates have received compromised network access from initial access brokers using the FortiBleed campaign against exposed Fortinet FortiGate firewalls and SSL VPN gateways. That access chain relies on previously compromised credentials, credential stuffing, password spraying, and offline password-hash cracking, providing footholds for subsequent ransomware deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SOCRadar published a lengthy study in July detailing how affiliates of the INC and Lynx groups were taking part in the campaign.
“Akira and Lynx: … Lynx might be a rebrand of the INC ransomware group.”
6 distinct techniques documented for this family, organized by ATT&CK tactic.
PsExec and direct access to administrative shares (ADMIN$, C$, etc.) remained present in some engagements... The most common approach involved executing the ransomware binary from a single compromised system — typically a domain controller or infrastructure server — and encrypting data on remote systems through administrative shares (ADMIN$, C$).
“Lynx… employs double extortion tactics… can steal sensitive information and encrypt the victim’s data…” / “Attackers typically encrypt systems after exfiltrating sensitive data.” / “Qilin follows a double extortion model — encrypting victims’ files and threatening to leak stolen data…”
ShinyHunters is a data extortion group specializing in large-scale data breaches and exposure of stolen datasets. In 2026, the group targeted healthcare-adjacent organizations, including medical technology companies, focusing on mass data exfiltration and leak-based extortion rather than encryption.
Des artefacts prouvent que l’acteur avait accès aux panneaux de négociation des ransomwares Lynx et INC... incluant des chats de négociation avec des victimes.
Prior to encryption, attackers systematically targeted backup infrastructure and virtualization platforms to maximize impact and eliminate recovery options: Hypervisors (VMware ESXi, Hyper-V) – Destruction or encryption of virtual machines at the hypervisor level; Backup infrastructure (Veeam) – Access via compromised privileged accounts or exploitation of known Veeam vulnerabilities to delete or encrypt backup repositories.
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
59 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware associated with activity linked to FortiBleed, illustrating how compromised FortiGate access can lead to ransomware operations. No family-specific technical behavior is provided.
Ransomware linked to the FortiBleed campaign through an exposed negotiation panel. Its operation is identified as benefiting from compromised Fortinet access, which the FBI says can provide initial entry for ransomware affiliates.
Ransomware whose operators reportedly purchase network footholds established through the FortiBleed credential-compromise campaign. The content does not describe its payload or encryption behavior.
Named ransomware whose affiliates are linked to purchasing access obtained through the FortiBleed credential-harvesting campaign. The article does not detail its technical behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.