Palo Alto Networks Unit 42 reported that the Lynx ransomware operation has emerged as a rebranding of INC Ransomware, indicating continuity rather than the appearance of a wholly new threat actor. The report links Lynx to INC through overlapping operational characteristics and branding changes, suggesting the group has shifted identity while maintaining its ransomware activity.
The rebrand matters for defenders because it can obscure attribution, complicate tracking of victimology and tactics, and create the impression of a new entrant in the ransomware ecosystem. Security teams should treat Lynx and INC Ransomware as closely connected in threat intelligence, detection, and incident response workflows while monitoring for continued evolution in infrastructure, tooling, and extortion operations.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published research assessing Lynx ransomware as a rebranding of the INC Ransomware operation, marking a new attribution development in the threat's evolution.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.