Overview
Platforms:
Windows · Linux · VMware ESXi
Variants:
Lynx
Extensions:
.lynx
ATT&CK software:
Cobalt Strike (S0154) · Mimikatz (S0002) · Rclone (S1040)
Initial access:
Valid Accounts
Top countries:
US · GB · CA · DE · AU
Observed sectors:
Manufacturing · Construction · Technology · Services · Automotive
Tracked victims:
418
Victims
cutlercapital
CLAIMED
Cutler Capital Management, LLC of Worcester, MA is an investment advisory firm registered with the Securities and Exchange Commission.
www.jerryleigh.com
CLAIMED
Jerry Leigh is a family-owned women's, men's, and children's clothing manufactur.
www.talbotdes.org
CLAIMED
Talbot County Department of Emergency Services provides essential emergency serv.
www.someco.com
CLAIMED
Southern Mechanical Contractors is a merit shop mechanical and industrial constr.
www.eastersealsia.org
CLAIMED
Easterseals Iowa provides an Assistive Technology Program that supports Iowans o.
Show more victims (12)
www.wolfconstruction.net
CLAIMED
Wolf Construction Services, Inc specializes in commercial wood framing, framing carpentry, wood trims, trim carpentry, and pitched roofing.
www.commonwealth-partners.com
CLAIMED
CommonWealth Partners Properties specializes in a range of real estate services including investment transactions, portfolio management, asset management.
bayareaherbs.com
CLAIMED
Bay Area Herbs & Specialties is a leading supplier of fresh culinary herbs and specialty produce, serving the US market for nearly 20 years.
jacksoncountyin.com
CLAIMED
Jackson County Visitor Center serves as a gateway for travelers seeking to explore the scenic beauty, rich history, and vibrant community of Jackson County, Indiana.
st-annes.uk.com
CLAIMED
St Anne's Catholic School & Sixth Form College is a distinguished educational in.
lifelongaccess.org
CLAIMED
Lifelong Access is a dedicated organization that supports individuals with disab.
www.kurita.eu
CLAIMED
Kurita Europe specializes in advanced water treatment technologies and sustainable solutions aimed at enhancing industrial and environmental efficiency.
ossistemes.com
CLAIMED
OS Sistemes is a tech company that helps businesses bring their digital projects to life.
csb-battery.com
CLAIMED
CSB Energy Technology Co., Ltd. is a leading global manufacturer of Valve-Regulated Lead-Acid (VRLA) batteries.
funkychunky.com
CLAIMED
Funky Chunky offers gourmet caramel corn and popcorn snacks, providing unique gift options perfect for various occasions such as business gatherings, birthdays.
sentrydynamics.com
CLAIMED
Sentry Dynamics, Inc. provides a powerful integrated suite of data solutions tai.
ACNHealthcare
CLAIMED
Revenue $253.6 Million We specialize in medical billing.
Operational Activity
TTPs
ATT&CK coverage:
6 techniques
T1078
Valid Accounts
VERIFIEDLynx-associated intrusions have used compromised administrative and remote-access credentials to obtain or maintain access to victim environments.
T1053.005
Scheduled Task
VERIFIEDLynx-associated operators have used Windows scheduled tasks to execute tooling and maintain persistence.
T1562.001
Impair Defenses
VERIFIEDLynx-associated operators have disabled or modified endpoint security products before ransomware deployment.
Show more TTPs (3)
T1021.001
Remote Desktop Protocol
VERIFIEDLynx-associated intrusion activity has used Remote Desktop Protocol for access and lateral movement inside compromised environments.
T1135
Network Share Discovery
VERIFIEDLynx tooling and intrusion activity support identification and targeting of accessible network shares before encryption.
T1490
Inhibit System Recovery
VERIFIEDLynx deletes Windows volume shadow copies and can remove virtualization snapshots to reduce victim recovery options.
CVEs
FortiCloud SSO SAML authentication bypass vulnerability associated with the FortiBleed campaign, which was attributed to the Lynx and INC ransomware operations.
Associated since:
July 2026
Infrastructure
Data Leak Site (DLS)
The group operates a dedicated Tor-based data leak site (often referred to as Lynx News) to publish exfiltrated data from non-paying victims.
ONLINE
Negotiation portal
Victims are directed to Tor-based negotiation portals via ransom notes (README.txt) left on compromised systems.
Attribution
INC Ransom
VERIFIED
Vendor tracking name
The ransomware family to which Lynx is linked. Lynx has been observed sharing significant source code and operational infrastructure with INC Ransom, leading to widespread assessment that Lynx is a successor or evolution of the INC operation.
Affiliates
TOXMAN
An affiliate who developed the PENTEST LAB framework, a 14-agent system used by the Lynx group for vulnerability research, CVE validation, credential checking, and attack playbook generation.
Timeline
2026-07
FortiBleed access ecosystem linked to Lynx
Researchers identified an operator associated with Fortinet credential theft logged into ransomware infrastructure connected with both INC and Lynx.
2025-01
Affiliate ecosystem documented
Group-IB published research into Lynx's affiliate panel, multi-platform ransomware arsenal, and operational workflow.
2025-01
Clutch Industries incident
Clutch Industries confirmed a cyber incident after Lynx claimed the organization and published data allegedly obtained from its environment.
Show more events (2)
2024-10
INC code lineage documented
Unit 42 documented substantial source-code and functional overlap between Lynx and INC ransomware, assessing Lynx as a successor to the earlier operation.
2024-07
Lynx emerges
Lynx ransomware samples and victim disclosures began appearing in July 2024.
Sources
Lynx Ransomware: A Rebranding of INC Ransomware
Palo Alto Networks Unit 42
Show more sources (15)
Lynx - Ransomware.live
Ransomware.live
Who is the Black Basta Ransomware Gang?
CybelAngel
Lynx Ransomware: Technical Analysis
Blackpoint Cyber
Clutch Industries Cyber Incident Statement
Clutch Industries