Lynx is a financially motivated ransomware operation active since at least 2024 and commonly referenced as Lynx, Lynxblog, or Lynx ransomware. It is widely assessed as closely related to INC Ransom, with reporting noting substantial code overlap between Lynx and INC ransomware samples and describing Lynx as a likely rebrand, evolution, or direct descendant of INC. The operation has been observed within the ransomware-as-a-service ecosystem and has been linked to shared operators and affiliate activity with INC Ransom. Lynx conducts ransomware and extortion attacks against organizations in multiple countries, including the United States and the United Kingdom, and has been noted as active in Europe. Reported victims span construction, industrial and mechanical services, real estate and business services, and healthcare-related organizations, indicating broad opportunistic targeting rather than a single vertical focus. The group is directly associated with downstream exploitation of access obtained through the FortiBleed campaign. Investigators linked an operator tied to FortiBleed infrastructure to active sessions in both INC Ransom and Lynx negotiation panels, providing strong evidence that stolen FortiGate credentials were operationalized for ransomware deployment. This connection places Lynx within a broader criminal supply chain in which credential harvesting and access brokering feed ransomware monetization. Operationally, Lynx is associated with initial access obtained through compromised credentials, post-compromise use of victim negotiation portals, and extortion workflows involving direct interaction with victims. Available evidence supports ransomware deployment and data breach activity against victims, and the group’s relationship with INC suggests shared tooling, infrastructure patterns, or affiliate resources. Lynx should be understood as part of a modular cybercrime ecosystem centered on access reuse, ransomware deployment, and extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS group linked to the FortiBleed campaign through shared affiliate TOXMAN, illustrating flexible affiliate-driven operations.
A possibly related ransomware/spin-off group alleged to share an identical code base with INC and potentially connected to the sale or rebranding of the INC project.
Mentioned as a ransomware group/sample set with significant code similarity to INC Ransom, suggesting a possible rebrand or close relationship.
Referenced as a ransomware operation directly linked to the FortiBleed campaign.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.