Researchers mapped the Lynx ransomware operation across multiple generations of Tor leak sites, negotiation portals, and victim communication channels, identifying 397 indexed victims between July 2024 and August 2026. The investigation linked historical leak pages, recurring ProtonMail addresses, malware-associated hidden services, and at least 14 additional Tor domains plus 16 more hidden services that followed the group’s naming patterns, indicating a structured and persistent ransomware infrastructure. Lynx has presented itself as a financially motivated group, but that claim remains unverified actor messaging.
Separate technical analysis describes Lynx as a ransomware-as-a-service operation that emerged in mid-2024 and appears related to the INC ransomware family, targeting sectors including finance, manufacturing, construction, and energy with double extortion. The malware reportedly encrypts files with AES in parallel threads, stores its ransom note in Base64, mounts hidden drives, changes wallpapers, prints ransom notes, and inhibits recovery by deleting Volume Shadow Copies, behavior aligned with MITRE ATT&CK technique T1490. That recovery-blocking tactic is widely associated with modern ransomware because it reduces victims’ ability to restore encrypted systems without paying.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
StealthMole historical records showed the current Lynx hidden service was still active as of 11 August 2026.
StealthMole historical records first observed the current Lynx leak-site hidden service on 20 August 2024.
StealthMole reports that one of the earliest indexed Lynx victim entries was published in August 2024, indicating public victim listings had begun by then.
StealthMole's ransomware monitoring indexed 397 Lynx victims between July 2024 and August 2026, showing sustained campaign activity over that period.
The ISH article states that the Lynx ransomware group emerged in mid-2024 and began operating as a ransomware-as-a-service scheme.
The ISH analysis describes Lynx as an evolution of the INC ransomware family and states that INC emerged in mid-2023.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 54 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
stealthmole-intelligence-hub.blogspot.com
Open sourceish.com.br
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.