Lynx is a ransomware family and associated ransomware-as-a-service operation that emerged in mid-2024 and is widely assessed as closely related to INC Ransom, with substantial code overlap suggesting derivation, rebranding, or evolution from the INC codebase after underground sales of INC source code. It operates as a double-extortion threat, combining file encryption with theft of victim data and coercive leak-site negotiations.
Lynx has been linked to intrusions across Windows and Linux or VMware ESXi environments, and reporting indicates overlap with sectors including retail, real estate, architecture, financial services, environmental services, energy, oil and gas, healthcare, and other enterprise targets. The operation has been described as affiliate-driven rather than a single closed actor, consistent with a RaaS model.
Observed and reported behavior includes encryption of victim files, exfiltration of sensitive information prior to encryption, deletion of backups or shadow copies to hinder recovery, and use of negotiation panels to manage extortion. Broader ecosystem reporting also ties Lynx to access obtained through credential-harvesting operations against perimeter infrastructure, particularly Fortinet environments, indicating that stolen credentials and compromised remote access may feed downstream Lynx deployments. Additional reporting places Lynx in attack chains where endpoint defenses are disabled before ransomware execution, reflecting common ransomware tradecraft focused on defense evasion and rapid impact.
Lynx is best understood as part of the broader post-2024 fragmentation and recombination of the ransomware ecosystem, where source-code reuse, affiliate migration, and shared tooling have complicated attribution between INC Ransom, Lynx, and other related families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Akira and Lynx: … Lynx might be a rebrand of the INC ransomware group.”
6 distinct techniques documented for this family, organized by ATT&CK tactic.
PsExec and direct access to administrative shares (ADMIN$, C$, etc.) remained present in some engagements... The most common approach involved executing the ransomware binary from a single compromised system — typically a domain controller or infrastructure server — and encrypting data on remote systems through administrative shares (ADMIN$, C$).
“Lynx… employs double extortion tactics… can steal sensitive information and encrypt the victim’s data…” / “Attackers typically encrypt systems after exfiltrating sensitive data.” / “Qilin follows a double extortion model — encrypting victims’ files and threatening to leak stolen data…”
ShinyHunters is a data extortion group specializing in large-scale data breaches and exposure of stolen datasets. In 2026, the group targeted healthcare-adjacent organizations, including medical technology companies, focusing on mass data exfiltration and leak-based extortion rather than encryption.
Des artefacts prouvent que l’acteur avait accès aux panneaux de négociation des ransomwares Lynx et INC... incluant des chats de négociation avec des victimes.
Prior to encryption, attackers systematically targeted backup infrastructure and virtualization platforms to maximize impact and eliminate recovery options: Hypervisors (VMware ESXi, Hyper-V) – Destruction or encryption of virtual machines at the hypervisor level; Backup infrastructure (Veeam) – Access via compromised privileged accounts or exploitation of known Veeam vulnerabilities to delete or encrypt backup repositories.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An emerging ransomware strain that surfaced or gained traction during 2025.
Named as a likely related ransomware/spin-off or rebrand sharing an identical code base with INC, possibly emerging after the alleged sale of the INC project.
Ransomware sample/family reported as highly similar to INC Ransom, with nearly half of analyzed functions overlapping according to BinDiff analysis.
Ransomware operation linked in the reporting to FortiBleed-derived access via an operator observed logged into its negotiation panel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.