Lynx is a ransomware family/group first observed in mid-2024 that operates under a ransomware-as-a-service model and uses double extortion, combining file encryption with data exfiltration and leak-site pressure. Multiple sources in the content assess Lynx as closely related to, evolved from, or possibly a rebrand of INC Ransom; it reportedly emerged after the 2024 underground sale of INC Windows and Linux/ESXi source code, and substantial code overlap with INC is repeatedly noted. One source states Lynx shares 48% of its source code with INC.
Reported capabilities include encrypting victim data, stealing sensitive information, appending the .lynx extension to encrypted files, deleting shadow copies/backups, terminating processes, mounting hidden drives, encrypting files on network shares, and printing ransom notes on printers. The content also places Lynx in observed attack chains where an EDR-killer is deployed before ransomware execution.
Initial access and delivery methods mentioned for Lynx-related activity include phishing emails, exploitation of public-facing systems, and use of stolen or brokered credentials. SOCRadar linked Lynx to the FortiBleed credential-harvesting campaign targeting Fortinet FortiGate devices: researchers reported an operator simultaneously logged into both INC and Lynx negotiation panels, overlap between FortiBleed victims and INC/Lynx-related activity, and downstream ransomware deployments following harvested FortiGate access. The FortiBleed reporting ties Lynx-associated activity to large-scale compromise of FortiGate environments across more than 150 countries.
Targeting described in the content includes healthcare, retail, real estate, architecture, financial services, environmental services, and U.S. energy/oil-and-gas-related facilities. The content also notes healthcare intrusions in 2026 and broader activity in the U.S. and UK. High-confidence identifiers directly mentioned include the .lynx file extension and the use of Lynx negotiation/admin panels observed in screenshots from FortiBleed infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Akira and Lynx: … Lynx might be a rebrand of the INC ransomware group.”
6 distinct techniques documented for this family, organized by ATT&CK tactic.
PsExec and direct access to administrative shares (ADMIN$, C$, etc.) remained present in some engagements... The most common approach involved executing the ransomware binary from a single compromised system — typically a domain controller or infrastructure server — and encrypting data on remote systems through administrative shares (ADMIN$, C$).
“Lynx… employs double extortion tactics… can steal sensitive information and encrypt the victim’s data…” / “Attackers typically encrypt systems after exfiltrating sensitive data.” / “Qilin follows a double extortion model — encrypting victims’ files and threatening to leak stolen data…”
ShinyHunters is a data extortion group specializing in large-scale data breaches and exposure of stolen datasets. In 2026, the group targeted healthcare-adjacent organizations, including medical technology companies, focusing on mass data exfiltration and leak-based extortion rather than encryption.
Des artefacts prouvent que l’acteur avait accès aux panneaux de négociation des ransomwares Lynx et INC... incluant des chats de négociation avec des victimes.
Prior to encryption, attackers systematically targeted backup infrastructure and virtualization platforms to maximize impact and eliminate recovery options: Hypervisors (VMware ESXi, Hyper-V) – Destruction or encryption of virtual machines at the hypervisor level; Backup infrastructure (Veeam) – Access via compromised privileged accounts or exploitation of known Veeam vulnerabilities to delete or encrypt backup repositories.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation linked in the reporting to FortiBleed-derived access via an operator observed logged into its negotiation panel.
Ransomware family/group that appeared in mid-2024 and is considered in the content to be a rebrand of INC Ransom.
A ransomware family linked in this report to FortiBleed-derived access; described as likely released as an updated variant a year after INC Ransom emerged.
A ransomware operation linked in the article to FortiBleed-derived access and described as widely assessed as an evolved variant of INC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.