โ Lynx¶
Threat-actor battle card ยท maintained from public sources ยท last updated 2026-08-17
Overview¶
Lynx is a Ransomware-as-a-Service operation that emerged in July 2024 and is now confirmed as a direct rebrand of the INC Ransomware operation, whose source code was reportedly sold on the RAMP cybercrime forum for $300,000 in May 2024. The confirmation came in July 2026: FortiBleed forensics (Unit 42/Fortinet PSIRT) observed a single operator simultaneously logged into both an INC Ransom negotiation panel and a Lynx negotiation panel during active negotiations โ direct operational evidence, not just code analysis. Unit 42 analysis had already confirmed roughly half of Lynx's codebase maps directly to INC, with even greater overlap in the Linux/ESXi variant. The group reached ~393โ410 victims across 20+ countries through June 2026; last known DLS post was June 18, 2026. The United States accounts for 208 victims (~53%), Canada 20, with the balance spread across Europe and APAC. Top sectors: Business Services (80 victims), Manufacturing (79), Technology (41), Transportation (29). Lynx is a named co-threat alongside Akira in targeting MSPs โ shared preference for RDP/credential-based access makes MSP fleets a high-leverage entry point for both groups. Lynx publicly claims to avoid healthcare, government, and non-profits โ a self-imposed restriction it has violated in practice.
Tradecraft¶
- RaaS model with an 80% affiliate revenue share โ a competitive payout designed to attract displaced talent from disrupted groups (LockBit, ALPHV, RansomHub).
- Initial access: phishing emails with malicious attachments, RDP brute-force against exposed endpoints, credential stuffing using infostealer logs, and purchased credentials from dark-web markets.
- Exploited CVEs (2024): CVE-2024-54085 and CVE-2024-0769 in internet-facing systems.
- Encryption: Curve25519/ChaCha20 hybrid; appends
.LYNXextension to encrypted files; drops a Base64-encoded ransom note. - Linux/ESXi variant โ code largely inherited from INC Ransomware, enabling mass-encryption of virtualised infrastructure.
- Double extortion: data exfiltrated before encryption, staged on DLS with escalating deadlines.
- CIS exclusion clause appears to be in place; affiliates appear to respect it more consistently than the "ethical" sector restrictions.
- FortiBleed campaign (July 2026): confirmed INC Ransom and Lynx negotiation panels operated simultaneously by the same actor during active victim negotiations โ establishing beyond code analysis that the groups share an operator. Campaign deployed ransomware on 12+ of the 86,644 compromised FortiGate devices; a credential server holding ~73,000 harvested credential sets was left publicly exposed; ~110M credential pairs exfiltrated via FortiGate Sniffer across the full campaign (CVE-2026-24858, CVSS 9.8). Downstream intrusion risk from credential reuse is a multi-quarter exposure across the affected credential inventory (confirmed to include Chevron, Samsung, AT&T, Comcast).
- SonicWall SMA 1000 campaign (August 2026): INC (same operator) is the dominant actor exploiting CVE-2026-15409 (CVSS 10.0, pre-auth WebSocket tunnel) chained with CVE-2026-15410 (CVSS 7.2, path traversal to root). Zero-day exploitation began June 22; patched and added to CISA KEV July 14. INC's distinctive tactic in this campaign: extracting TOTP MFA seed configurations from SMA appliances alongside session databases and credentials, enabling persistent authenticated access that survives password resets. Post-exploitation includes direct victim phone calls as a pressure tactic. 893+ total INC victims as of August 10, 38 new in the prior 30 days. New victims span Australia, US, UAE, Colombia, Switzerland. [Resecurity, The Hacker News, SC Media โ August 2026]
Notable victims¶
- Electrica Group (Romania; major electricity supplier serving 3.8M citizens; Dec 2024) โ CIS Security
- DZS Inc. (US; global network-solutions vendor; $18.1M ransom demanded; ~30GB exfiltrated; 2024) โ Halcyon
- Hunter Taubman Fischer & Li LLC (US law firm specialising in corporate and securities law; Jan 2025) โ SOCRadar
- CONAD (Italy; major retail chain; Jan 2025) โ Picus Security
- Zamzows, Inc. (US; Idaho-based lawn, garden and pet-supply retail chain; Feb 2025) โ Cyble
Assessment¶
A mature, fast-scaling RaaS operation with its INC Ransomware lineage now operationally confirmed rather than inferred from code analysis. The July 2026 FortiBleed forensics โ a shared operator simultaneously active in both INC Ransom and Lynx negotiation panels โ is the most significant ransomware rebrand confirmation of 2026; defenders who attributed incidents only to one brand have been tracking half the actor's footprint. The 80% affiliate cut makes Lynx a magnet for talent displaced from disrupted groups. The ESXi variant enables rapid virtualisation-layer encryption, extending blast radius well beyond Windows endpoints. Energy and utilities targeting โ confirmed by an attack on Romania's largest electricity supplier โ makes this relevant for critical-infrastructure portfolios. The Acronis/Halcyon finding that MSPs are a top shared target with Akira is significant: a compromised MSP multiplies exposure across all of its managed tenants. CIS exclusion and stated sector restrictions match Eastern European criminal norms but provide no protection for Western enterprise. Lynx's DLS has been quiet since June 18, 2026, but the INC operator is demonstrably not idle โ the FortiBleed credential harvest and the August SonicWall MFA-seed campaign show the same actor escalating toward infrastructure-level, persistence-first access operations. The MFA seed theft is particularly significant: it means remediation of a SonicWall intrusion requires replacing hardware or wiping and re-provisioning TOTP seeds, not just rotating passwords. Priority defences: RDP hardening and MFA; infostealer credential monitoring (dark-web feeds); ESXi network segmentation; offline backup integrity verification; heightened MSP-specific controls (PAM, client network isolation); any organisation with FortiGate devices should treat the FortiBleed credential exposure period (pre-CVE-2026-24858 patch) as a presumed-access window requiring full credential rotation.
Sources¶
- Unit 42 โ Lynx: INC Ransomware Rebrand
- Halcyon โ Lynx threat group profile
- FortiGuard Labs โ Ransomware Roundup: Lynx
- CIS Security โ Lynx Ransomware Pouncing on Utilities
- Picus Security โ Lynx: How INC Ransomware Rebrands Itself
- SOCRadar โ Dark Web Profile: Lynx Ransomware
- Cyble โ Lynx Ransomware Threat Actor Profile
- Darktrace โ New Threat on the Prowl: Investigating Lynx Ransomware
- Acronis โ MSPs a top target for Akira and Lynx ransomware
- Intel 471 โ Lynx Ransomware
- ransomware.live โ Lynx group page
- BleepingComputer โ FortiBleed: INC Ransom and Lynx operated by same actor
- SOCRadar โ FortiBleed investigation: 73K credential server, INC=Lynx confirmation
- Resecurity โ From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain
- The Hacker News โ INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
- SC Media โ INC Ransomware chains two SonicWall SMA 1000 zero-days
๐๏ธ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
No attacks recorded yet.