Lynx is a ransomware operation active since at least 2024 and commonly referenced under aliases including LynxBlog and lynx_ransomware. It is closely linked to INC Ransom and is widely assessed as either a rebrand, direct evolution, or code-sharing successor of that operation. Malware analysis has shown substantial overlap between INC Ransom and Lynx samples, including significant shared functionality, and operational reporting has tied the two groups together through shared affiliate activity and common downstream use of externally obtained access. Lynx operates within the ransomware-as-a-service ecosystem and has been associated with victim negotiation panels, leak-site activity, and data-breach-style extortion. Reporting directly connects Lynx to the FortiBleed campaign through an operator observed accessing both FortiBleed infrastructure and the negotiation panels used by Lynx and INC Ransom. That linkage indicates Lynx has benefited from access obtained through large-scale credential harvesting against Fortinet environments and subsequent intrusion activity. In multiple confirmed cases, such access progressed from perimeter compromise to broader enterprise intrusion and ransomware deployment. Observed victimology shows Lynx targeting organizations in the United States, the United Kingdom, Germany, and Singapore, with broader emphasis on Europe and repeated targeting of German companies. Confirmed victims span government and public-sector emergency services, health care, industrial and construction-related firms, apparel manufacturing, and real-estate or business-services organizations. Broader reporting also places Lynx among the more active ransomware operations in Europe during 2026. Capabilities directly associated with Lynx include initial access through compromised credentials supplied by upstream access operations, persistence, credential theft, network sniffing through linked campaigns, data exfiltration, and ransomware deployment for extortion. The group is tied to post-compromise enterprise intrusion activity that can include progression from VPN or firewall access into domain environments and victim negotiation workflows. The dominant motivation is financial.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Jerry Leigh, a US-based clothing manufacturer and brand management company.
Conducting a ransomware attack resulting in a data breach against Talbot County Department of Emergency Services.
RaaS group linked to the FortiBleed campaign through shared affiliate TOXMAN, illustrating flexible affiliate-driven operations.
A possibly related ransomware/spin-off group alleged to share an identical code base with INC and potentially connected to the sale or rebranding of the INC project.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.