Overview

Platforms: Windows · Linux · VMware ESXi
Variants: Lynx
Extensions: .lynx
ATT&CK software: Cobalt Strike (S0154) · Mimikatz (S0002) · Rclone (S1040)
Initial access: Valid Accounts
Top countries: US · GB · CA · DE · AU
Observed sectors: Manufacturing · Construction · Technology · Services · Automotive
Tracked victims: 418

Victims

cutlercapital CLAIMED
August 27, 2026 US Wealth Management 3 tracker sources
Cutler Capital Management, LLC of Worcester, MA is an investment advisory firm registered with the Securities and Exchange Commission.
www.jerryleigh.com CLAIMED
August 6, 2026 US Apparel 3 tracker sources
Jerry Leigh is a family-owned women's, men's, and children's clothing manufactur.
www.talbotdes.org CLAIMED
August 6, 2026 GB Digital infrastructures 3 tracker sources
Talbot County Department of Emergency Services provides essential emergency serv.
www.someco.com CLAIMED
June 18, 2026 US Unknown 3 tracker sources
Southern Mechanical Contractors is a merit shop mechanical and industrial constr.
www.eastersealsia.org CLAIMED
June 18, 2026 US Technology 3 tracker sources
Easterseals Iowa provides an Assistive Technology Program that supports Iowans o.
Show more victims (12)
www.wolfconstruction.net CLAIMED
June 18, 2026 US Construction 3 tracker sources
Wolf Construction Services, Inc specializes in commercial wood framing, framing carpentry, wood trims, trim carpentry, and pitched roofing.
www.commonwealth-partners.com CLAIMED
June 11, 2026 GB Finance 3 tracker sources
CommonWealth Partners Properties specializes in a range of real estate services including investment transactions, portfolio management, asset management.
bayareaherbs.com CLAIMED
May 10, 2026 US Agriculture & Food 3 tracker sources
Bay Area Herbs & Specialties is a leading supplier of fresh culinary herbs and specialty produce, serving the US market for nearly 20 years.
jacksoncountyin.com CLAIMED
May 10, 2026 US Local administrations 3 tracker sources
Jackson County Visitor Center serves as a gateway for travelers seeking to explore the scenic beauty, rich history, and vibrant community of Jackson County, Indiana.
st-annes.uk.com CLAIMED
May 10, 2026 GB Schools 3 tracker sources
St Anne's Catholic School & Sixth Form College is a distinguished educational in.
lifelongaccess.org CLAIMED
May 10, 2026 US Human Services 3 tracker sources
Lifelong Access is a dedicated organization that supports individuals with disab.
www.kurita.eu CLAIMED
May 10, 2026 DE Manufacturing 3 tracker sources
Kurita Europe specializes in advanced water treatment technologies and sustainable solutions aimed at enhancing industrial and environmental efficiency.
ossistemes.com CLAIMED
May 10, 2026 ES Information Technologies Consulting 3 tracker sources
OS Sistemes is a tech company that helps businesses bring their digital projects to life.
csb-battery.com CLAIMED
May 10, 2026 TW Manufacturing 3 tracker sources
CSB Energy Technology Co., Ltd. is a leading global manufacturer of Valve-Regulated Lead-Acid (VRLA) batteries.
funkychunky.com CLAIMED
May 10, 2026 US Food and drinks businesses 3 tracker sources
Funky Chunky offers gourmet caramel corn and popcorn snacks, providing unique gift options perfect for various occasions such as business gatherings, birthdays.
sentrydynamics.com CLAIMED
April 13, 2026 US Technology 3 tracker sources
Sentry Dynamics, Inc. provides a powerful integrated suite of data solutions tai.
ACNHealthcare CLAIMED
April 8, 2026 IN Healthcare 3 tracker sources
Revenue $253.6 Million We specialize in medical billing.

Operational Activity

TTPs

ATT&CK coverage: 6 techniques
T1078 Valid Accounts
VERIFIED
Lynx-associated intrusions have used compromised administrative and remote-access credentials to obtain or maintain access to victim environments.
T1053.005 Scheduled Task
VERIFIED
Lynx-associated operators have used Windows scheduled tasks to execute tooling and maintain persistence.
T1562.001 Impair Defenses
VERIFIED
Lynx-associated operators have disabled or modified endpoint security products before ransomware deployment.
Show more TTPs (3)
T1021.001 Remote Desktop Protocol
VERIFIED
Lynx-associated intrusion activity has used Remote Desktop Protocol for access and lateral movement inside compromised environments.
T1135 Network Share Discovery
VERIFIED
Lynx tooling and intrusion activity support identification and targeting of accessible network shares before encryption.
T1490 Inhibit System Recovery
VERIFIED
Lynx deletes Windows volume shadow copies and can remove virtualization snapshots to reduce victim recovery options.

CVEs

FortiCloud SSO SAML authentication bypass vulnerability associated with the FortiBleed campaign, which was attributed to the Lynx and INC ransomware operations.
Associated since: July 2026

Infrastructure

Data Leak Site (DLS)
The group operates a dedicated Tor-based data leak site (often referred to as Lynx News) to publish exfiltrated data from non-paying victims.
ONLINE
Negotiation portal
Victims are directed to Tor-based negotiation portals via ransom notes (README.txt) left on compromised systems.

Attribution

INC Ransom VERIFIED
Vendor tracking name
The ransomware family to which Lynx is linked. Lynx has been observed sharing significant source code and operational infrastructure with INC Ransom, leading to widespread assessment that Lynx is a successor or evolution of the INC operation.

Affiliates

TOXMAN
An affiliate who developed the PENTEST LAB framework, a 14-agent system used by the Lynx group for vulnerability research, CVE validation, credential checking, and attack playbook generation.

Timeline

2026-07
FortiBleed access ecosystem linked to Lynx
Researchers identified an operator associated with Fortinet credential theft logged into ransomware infrastructure connected with both INC and Lynx.
2025-01
Affiliate ecosystem documented
Group-IB published research into Lynx's affiliate panel, multi-platform ransomware arsenal, and operational workflow.
2025-01
Clutch Industries incident
Clutch Industries confirmed a cyber incident after Lynx claimed the organization and published data allegedly obtained from its environment.
Show more events (2)
2024-10
INC code lineage documented
Unit 42 documented substantial source-code and functional overlap between Lynx and INC ransomware, assessing Lynx as a successor to the earlier operation.
2024-07
Lynx emerges
Lynx ransomware samples and victim disclosures began appearing in July 2024.

Sources