Lynx is a ransomware family and associated ransomware-as-a-service operation that emerged in mid-2024 and is widely assessed as closely related to INC Ransom, with substantial code overlap and likely lineage from the sale of INC source code. It operates a double-extortion model in which victim data is exfiltrated and systems are encrypted, with stolen data used to pressure victims through leak-site publication and negotiation channels. Lynx has been observed targeting organizations across multiple sectors, including finance, manufacturing, architecture and construction, energy, and healthcare, with global victimization.
The malware is a Windows ransomware encryptor that uses AES for file encryption and multithreaded execution to accelerate impact. Reported behaviors include enumerating systems, processes, network resources, and volumes; mounting hidden drives for subsequent encryption; deleting shadow-copy data to inhibit recovery; terminating processes or services that may interfere with encryption; changing the desktop wallpaper to a ransom message; and printing ransom instructions to local printers. Analysis also indicates selective file and directory exclusions intended to preserve system operability while maximizing extortion leverage.
Lynx is associated with affiliate-driven intrusion activity rather than a single fixed access vector. Reporting links the broader Lynx ecosystem to credential-harvesting operations such as FortiBleed, and to shared operator or affiliate overlap with INC Ransom. Additional reporting places Lynx in attack chains where endpoint defenses are disabled before ransomware execution, indicating use alongside EDR-killer tooling in some intrusions. The operation is part of the broader post-2024 fragmentation of the ransomware ecosystem, where related codebases, affiliates, and infrastructure overlap complicate attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Akira and Lynx: … Lynx might be a rebrand of the INC ransomware group.”
6 distinct techniques documented for this family, organized by ATT&CK tactic.
PsExec and direct access to administrative shares (ADMIN$, C$, etc.) remained present in some engagements... The most common approach involved executing the ransomware binary from a single compromised system — typically a domain controller or infrastructure server — and encrypting data on remote systems through administrative shares (ADMIN$, C$).
“Lynx… employs double extortion tactics… can steal sensitive information and encrypt the victim’s data…” / “Attackers typically encrypt systems after exfiltrating sensitive data.” / “Qilin follows a double extortion model — encrypting victims’ files and threatening to leak stolen data…”
ShinyHunters is a data extortion group specializing in large-scale data breaches and exposure of stolen datasets. In 2026, the group targeted healthcare-adjacent organizations, including medical technology companies, focusing on mass data exfiltration and leak-based extortion rather than encryption.
Des artefacts prouvent que l’acteur avait accès aux panneaux de négociation des ransomwares Lynx et INC... incluant des chats de négociation avec des victimes.
Prior to encryption, attackers systematically targeted backup infrastructure and virtualization platforms to maximize impact and eliminate recovery options: Hypervisors (VMware ESXi, Hyper-V) – Destruction or encryption of virtual machines at the hypervisor level; Backup infrastructure (Veeam) – Access via compromised privileged accounts or exploitation of known Veeam vulnerabilities to delete or encrypt backup repositories.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware ecosystem whose affiliate was observed deploying DeadLock ransomware.
An emerging ransomware strain that surfaced or gained traction during 2025.
Named as a likely related ransomware/spin-off or rebrand sharing an identical code base with INC, possibly emerging after the alleged sale of the INC project.
Ransomware sample/family reported as highly similar to INC Ransom, with nearly half of analyzed functions overlapping according to BinDiff analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.