SOCRadar published a lengthy study in July detailing how affiliates of the INC and Lynx groups were taking part in the campaign.
Lynx
Lynx is a ransomware family associated with a ransomware-as-a-service operation that emerged in mid-2024.
Lynx
Family profile
Lynx is a ransomware family associated with a ransomware-as-a-service operation that emerged in mid-2024. It shares substantial code with INC Ransom, demonstrating a close technical relationship between the families. Lynx affiliates conduct double-extortion attacks, encrypting victim systems and stealing data for threatened publication on a Tor-based leak site. The operation targets organizations internationally, including finance, manufacturing, architecture and construction, and energy. Affiliates have obtained compromised network access through initial access brokers associated with FortiBleed, a credential-compromise campaign targeting Fortinet FortiGate firewalls and SSL VPN gateways.
Analyzed Windows variants use multithreaded AES file encryption and can discover and mount hidden volumes to expand encryption coverage. Lynx enumerates files, systems, network shares, and processes, and inhibits recovery by deleting Volume Shadow Copy data through DeviceIoControl rather than conventional command-line utilities. It decodes an embedded Base64 ransom note, changes the desktop wallpaper to display ransom instructions, and can print ransom notes through local printers. Selected file types and directories are excluded from encryption to preserve system functionality.
Capabilities
- Exfiltration
- Extortion
- Reconnaissance
Samples
Recent samples
2 sandbox samples in the Derp library, newest 2 shown
Reported operators
Threat actors
2 named in public reporting“Akira and Lynx: … Lynx might be a rebrand of the INC ransomware group.”
MITRE ATT&CK
Lynx in ATT&CK
6 distinct techniquesReporting
Research mentioning Lynx
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure - Malware News - Malware Analysis, News and Indicators
Microsoft reported that the DeadLock ransomware operation has emerged as a financially motivated threat using double extortion and a decentralized recovery ecosystem designed to resist disruption. First observed in July 2025, DeadLock had listed more than 80 claimed victims by July 2026, with over half in Europe, and has affected organizations across multiple sectors and regions. Microsoft said the malware has been deployed by multiple groups, including an affiliate tied to the Lynx and INC ransomware ecosystems. The Rust-based encryptor combines common ransomware tradecraft with an unusual communications and leak infrastructure. Microsoft said DeadLock attempts privilege escalation, terminates services and processes, clears event logs, selectively encrypts files, drops ransom notes, and self-deletes, while its recovery workflow relies on a local HTML chat app, the Session messaging network, Polygon smart contracts for configuration and blog data, and Wasabi-hosted stolen files exposed through an S3-compatible browser. The company also described DeadLock's hybrid cryptography using Curve25519 and XChaCha20 with per-file ephemeral keys, assessing the scheme as cryptographically sound and leaving no practical decryption path without the attackers' private key.