Discovery Enum
- SoftPerfect NetScan
Lynx is a ransomware family and ransomware-as-a-service operation that emerged in mid-2024 and is widely assessed to be closely related to, or a rebrand/evolved descendant of, INC Ransom.
Profile source: Mallory opens in a new tabLynx
Lynx is a ransomware family and ransomware-as-a-service operation that emerged in mid-2024 and is widely assessed to be closely related to, or a rebrand/evolved descendant of, INC Ransom. Multiple analyses report substantial code overlap between Lynx and INC, including shared functionality and lineage tied to the 2024 underground sale of INC ransomware source code. Lynx has been associated with double-extortion operations in which attackers steal data before encrypting systems and then pressure victims through negotiation portals and leak-site exposure.
Lynx targets enterprise environments and has been observed affecting organizations across sectors including retail, real estate, architecture, financial services, environmental services, healthcare, and energy-related organizations. Reported victim geography includes the United States and the United Kingdom, and broader reporting places Lynx among active ransomware strains gaining traction through 2025 and remaining relevant in 2026.
Operationally, Lynx is linked to the broader ransomware affiliate ecosystem rather than a single tightly bounded actor. It has been connected to infrastructure and operator overlap with INC Ransom, including reporting that a shared operator accessed both INC and Lynx negotiation panels. Lynx has also appeared in intrusion chains where endpoint defenses were disabled before ransomware execution, indicating use within mature post-compromise workflows.
Behavior attributed to Lynx includes encrypting victim data, appending a distinct file extension to encrypted files, deleting backups such as shadow copies to hinder recovery, and supporting extortion through victim negotiation channels. High-confidence reporting also ties Lynx to incidents where credential-harvesting operations against perimeter infrastructure fed access into later ransomware deployment, reinforcing its role as a downstream payload in access-brokered intrusions.
The strongest evidence supports classifying Lynx as a Windows-focused ransomware family with double-extortion tradecraft and close technical and operational ties to INC Ransom.
b1d81e8bbecccc547645d17395538a2da20886a5b378624d16972db66bd4e7e1f16238836909d07f86154c5ccbade96a30656c737338818bee8cc3591e3f3dcc571684f28ce1cf4d8236dbd46ef6f7f065c0c7c9fe6bc1d5296447aae6c6c14cd972bbbb3edb0e5ab5751b911f3dda17146d350fd6271b4411714c630d8cda87ff458208c49836cdec92f0a4a7ba6afd67a44a38cc36becd6e2e9c20c27fd9adReported operators
“Akira and Lynx: … Lynx might be a rebrand of the INC ransomware group.”
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.