HackerFeeds
All ransomware groups

lynx

414 tracked victims
·first seen 2023-05-22·last activity 2026-06-18

Group profile

Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300,000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Compromised credentials purchased from initial access brokers used to authenticate via RDP and VPN.

  • T1566.001Phishing: Spearphishing Attachment

    Lynx uses phishing emails with malicious attachments to deliver initial access stagers.

TA0002

Execution

  • T1059.001Command and Scripting Interpreter: PowerShell

    PowerShell used for payload execution and post-exploitation activity.

TA0005

Defense Evasion

  • T1036Masquerading

    Lynx ransomware binary renamed to blend into normal file system activity; masquerades as legitimate utilities.

  • T1562.001Disable or Modify Tools

    Security tools disabled before ransomware deployment.

TA0006

Credential Access

  • T1003.001OS Credential Dumping: LSASS Memory

    Credential dumping from LSASS used to facilitate lateral movement.

TA0007

Discovery

  • T1012Query Registry

    Registry queried to identify installed security software and system configuration before encryption.

  • T1082System Information Discovery

    Lynx queries CPU information and system details to assess the target environment and check for sandbox/analysis conditions.

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    RDP used for lateral movement with harvested credentials.

TA0010

Exfiltration

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

    Data exfiltrated for double extortion via the Lynx leak site prior to encryption.

TA0011

Command and Control

  • T1071.001Application Layer Protocol: Web Protocols

    C2 communication over HTTPS; Tor used for victim negotiation portals.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Lynx uses AES-128 CTR mode for file encryption with RSA-2048 for key protection. Code similarities indicate it may be a rebrand or fork of INC Ransomware. Emerged mid-2024; highly aggressive targeting of SMBs and mid-market organizations across multiple sectors. Appends .lynx extension.

  • T1490Inhibit System Recovery

    Shadow copies deleted and recovery options disabled to prevent victim restoration.

Recent victims

showing 50 of 414
DateWebsite / victimSectorCountry
2026-06-18
someco.com
www.someco.comwww.someco.com
Not Found
2026-06-18
eastersealsia.org
www.eastersealsia.orgwww.eastersealsia.org
HealthcareUS
2026-06-18
wolfconstruction.net
www.wolfconstruction.netwww.wolfconstruction.net
ConstructionUS
2026-06-11
commonwealth-partners.com
www.commonwealth-partners.comwww.commonwealth-partners.com
Business ServicesGB
2026-05-10
lifelongaccess.org
lifelongaccess.orglifelongaccess.org
HealthcareUS
2026-05-10
st-annes.uk.com
st-annes.uk.comst-annes.uk.com
EducationGB
2026-05-10
bayareaherbs.com
bayareaherbs.combayareaherbs.com
Consumer ServicesUS
2026-05-10
jacksoncountyin.com
jacksoncountyin.comjacksoncountyin.com
Public SectorUS
2026-05-10
ossistemes.com
ossistemes.comossistemes.com
TechnologyES
2026-05-10
csb-battery.com
csb-battery.comcsb-battery.com
ManufacturingTW
2026-05-10
funkychunky.com
funkychunky.comfunkychunky.com
Consumer ServicesUS
2026-05-10
kurita.eu
www.kurita.euwww.kurita.eu
ManufacturingDE
2026-04-06ConstructionGB
2026-03-29
cwwcontractors.com
cwwcontractors.comcwwcontractors.com
ConstructionGB
2026-04-13
sentrydynamics.com
sentrydynamics.comsentrydynamics.com
TechnologyUS
2026-04-08
acnhealthcare.com
ACNHealthcareacnhealthcare.com
HealthcareIN
2026-04-07
smithdollar.com
www.smithdollar.comwww.smithdollar.com
Financial ServicesUS
2026-03-17
njpcs.org
njpcs.orgnjpcs.org
EducationUS
2026-03-12
indrub.com
indrub.comindrub.com
ManufacturingIN
2026-02-28ConstructionPL
2026-03-06
africainsurance.com
Africa Insurancewww.africainsurance.com
Financial ServicesET
2026-03-01
hegelmann.com
https://www.hegelmann.comhegelmann.com
Transportation/LogisticsDE
2026-02-10Business ServicesES
2026-02-17ManufacturingRO
2026-02-11
keylogistics.cl
Keylogistics Chilekeylogistics.cl
Transportation/LogisticsCL
2026-02-12
secure.ae
secure.aesecure.ae
Not FoundAE
2026-02-17
gbaco.com
gbaco.comgbaco.com
Financial ServicesGB
2026-02-17
powersmiller.com
powersmiller.compowersmiller.com
Business ServicesUS
2026-02-17
structuredassetservices.com
structuredassetservices.comstructuredassetservices.com
Financial ServicesUS
2026-01-30Agriculture and Food ProductionES
2026-02-04
trisa.ch
www.trisa.chwww.trisa.ch
ManufacturingCH
2026-02-03
peterboroughpublichealth.ca
peterboroughpublichealth.capeterboroughpublichealth.ca
Public SectorCA
2026-01-30
shorelinenyc.com
shorelinenyc.comshorelinenyc.com
Hospitality and TourismUS
2026-01-30
roschvisionary.com
www.roschvisionary.comwww.roschvisionary.com
TechnologyDE
2026-01-14Agriculture and Food ProductionRO
2026-01-04Transportation/LogisticsES
2025-12-31Business ServicesCA
2026-01-06
swautomation.at
www.swautomation.atwww.swautomation.at
ManufacturingAT
2026-01-05
burdettedental.com
www.burdettedental.comwww.burdettedental.com
HealthcareUS
2026-01-05
tecnoelectric.com.py
www.tecnoelectric.com.pywww.tecnoelectric.com.py
ManufacturingPY
2026-01-05
sje.vic.edu.au
www.sje.vic.edu.auwww.sje.vic.edu.au
EducationAU
2026-01-05
granosycereales.com.co
www.granosycereales.com.cowww.granosycereales.com.co
Agriculture and Food ProductionCO
2026-01-05
ville-dunkerque.fr
www.ville-dunkerque.frwww.ville-dunkerque.fr
Public SectorFR
2026-01-05
mscorp.net
www.mscorp.netwww.mscorp.net
TechnologyUS
2026-01-05
mcphillamysgold.com
www.mcphillamysgold.comwww.mcphillamysgold.com
EnergyAU
2026-01-05
blackdogsalvage.com
www.blackdogsalvage.comwww.blackdogsalvage.com
Consumer ServicesUS
2026-01-05
crawfordorthodontics.net
crawfordorthodontics.netcrawfordorthodontics.net
HealthcareUS
2026-01-05
stcharlesprep.org
www.stcharlesprep.orgwww.stcharlesprep.org
EducationUS
2026-01-05
laurysenkitchens.com
laurysenkitchens.comlaurysenkitchens.com
ManufacturingCA
2026-01-05
miltonfl.org
miltonfl.orgmiltonfl.org
Public SectorUS