Skip to content

Lynx

Lynx is a ransomware family and associated ransomware-as-a-service operation that emerged in mid-2024 and is widely assessed as closely related to INC Ransom, with substantial code overlap and likely lineage from the sale of INC source code.

Profile source: Mallory opens in a new tab

Lynx

Family profile

Lynx is a ransomware family and associated ransomware-as-a-service operation that emerged in mid-2024 and is widely assessed as closely related to INC Ransom, with substantial code overlap and likely lineage from the sale of INC source code. It operates a double-extortion model in which victim data is exfiltrated and systems are encrypted, with stolen data used to pressure victims through leak-site publication and negotiation channels. Lynx has been observed targeting organizations across multiple sectors, including finance, manufacturing, architecture and construction, energy, and healthcare, with global victimization.

The malware is a Windows ransomware encryptor that uses AES for file encryption and multithreaded execution to accelerate impact. Reported behaviors include enumerating systems, processes, network resources, and volumes; mounting hidden drives for subsequent encryption; deleting shadow-copy data to inhibit recovery; terminating processes or services that may interfere with encryption; changing the desktop wallpaper to a ransom message; and printing ransom instructions to local printers. Analysis also indicates selective file and directory exclusions intended to preserve system operability while maximizing extortion leverage.

Lynx is associated with affiliate-driven intrusion activity rather than a single fixed access vector. Reporting links the broader Lynx ecosystem to credential-harvesting operations such as FortiBleed, and to shared operator or affiliate overlap with INC Ransom. Additional reporting places Lynx in attack chains where endpoint defenses are disabled before ransomware execution, indicating use alongside EDR-killer tooling in some intrusions. The operation is part of the broader post-2024 fragmentation of the ransomware ecosystem, where related codebases, affiliates, and infrastructure overlap complicate attribution.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Reconnaissance

Operational record

19
Indicators
1
YARA rules
2
Ransom notes
10
Leak sites
8 available

Discovery Enum

  • SoftPerfect NetScan

Exfiltration

  • Restic

Published indicators

Md5

19 total
  • b1d81e8bbecccc547645d17395538a2d
  • a20886a5b378624d16972db66bd4e7e1
  • f16238836909d07f86154c5ccbade96a
  • 30656c737338818bee8cc3591e3f3dcc
  • 571684f28ce1cf4d8236dbd46ef6f7f0
  • 65c0c7c9fe6bc1d5296447aae6c6c14c
  • d972bbbb3edb0e5ab5751b911f3dda17
  • 146d350fd6271b4411714c630d8cda87
  • ff458208c49836cdec92f0a4a7ba6afd
  • 67a44a38cc36becd6e2e9c20c27fd9ad

Recent claims

Reported operators

Threat actors

1 named in public reporting
INC

“Akira and Lynx: … Lynx might be a rebrand of the INC ransomware group.”

MITRE ATT&CK

Lynx in ATT&CK

17 distinct techniques

Reporting

Research mentioning Lynx

Aug 10
Malware News

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure - Malware News - Malware Analysis, News and Indicators

Microsoft reported that the DeadLock ransomware operation has emerged as a financially motivated threat using double extortion and a decentralized recovery ecosystem designed to resist disruption. First observed in July 2025, DeadLock had listed more than 80 claimed victims by July 2026, with over half in Europe, and has affected organizations across multiple sectors and regions. Microsoft said the malware has been deployed by multiple groups, including an affiliate tied to the Lynx and INC ransomware ecosystems. The Rust-based encryptor combines common ransomware tradecraft with an unusual communications and leak infrastructure. Microsoft said DeadLock attempts privilege escalation, terminates services and processes, clears event logs, selectively encrypts files, drops ransom notes, and self-deletes, while its recovery workflow relies on a local HTML chat app, the Session messaging network, Polygon smart contracts for configuration and blog data, and Wasabi-hosted stolen files exposed through an S3-compatible browser. The company also described DeadLock's hybrid cryptography using Curve25519 and XChaCha20 with per-file ephemeral keys, assessing the scheme as cryptographically sound and leaving no practical decryption path without the attackers' private key.

Aug 10
Microsoft General

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure | Microsoft Security Blog

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.