Discovery Enum
- SoftPerfect NetScan
Lynx is a ransomware family and associated ransomware-as-a-service operation that emerged in mid-2024 and is widely assessed as closely related to INC Ransom, with substantial code overlap and likely lineage from the sale of INC source code.
Profile source: Mallory opens in a new tabLynx
Lynx is a ransomware family and associated ransomware-as-a-service operation that emerged in mid-2024 and is widely assessed as closely related to INC Ransom, with substantial code overlap and likely lineage from the sale of INC source code. It operates a double-extortion model in which victim data is exfiltrated and systems are encrypted, with stolen data used to pressure victims through leak-site publication and negotiation channels. Lynx has been observed targeting organizations across multiple sectors, including finance, manufacturing, architecture and construction, energy, and healthcare, with global victimization.
The malware is a Windows ransomware encryptor that uses AES for file encryption and multithreaded execution to accelerate impact. Reported behaviors include enumerating systems, processes, network resources, and volumes; mounting hidden drives for subsequent encryption; deleting shadow-copy data to inhibit recovery; terminating processes or services that may interfere with encryption; changing the desktop wallpaper to a ransom message; and printing ransom instructions to local printers. Analysis also indicates selective file and directory exclusions intended to preserve system operability while maximizing extortion leverage.
Lynx is associated with affiliate-driven intrusion activity rather than a single fixed access vector. Reporting links the broader Lynx ecosystem to credential-harvesting operations such as FortiBleed, and to shared operator or affiliate overlap with INC Ransom. Additional reporting places Lynx in attack chains where endpoint defenses are disabled before ransomware execution, indicating use alongside EDR-killer tooling in some intrusions. The operation is part of the broader post-2024 fragmentation of the ransomware ecosystem, where related codebases, affiliates, and infrastructure overlap complicate attribution.
b1d81e8bbecccc547645d17395538a2da20886a5b378624d16972db66bd4e7e1f16238836909d07f86154c5ccbade96a30656c737338818bee8cc3591e3f3dcc571684f28ce1cf4d8236dbd46ef6f7f065c0c7c9fe6bc1d5296447aae6c6c14cd972bbbb3edb0e5ab5751b911f3dda17146d350fd6271b4411714c630d8cda87ff458208c49836cdec92f0a4a7ba6afd67a44a38cc36becd6e2e9c20c27fd9adReported operators
“Akira and Lynx: … Lynx might be a rebrand of the INC ransomware group.”
MITRE ATT&CK
Reporting
Microsoft reported that the DeadLock ransomware operation has emerged as a financially motivated threat using double extortion and a decentralized recovery ecosystem designed to resist disruption. First observed in July 2025, DeadLock had listed more than 80 claimed victims by July 2026, with over half in Europe, and has affected organizations across multiple sectors and regions. Microsoft said the malware has been deployed by multiple groups, including an affiliate tied to the Lynx and INC ransomware ecosystems. The Rust-based encryptor combines common ransomware tradecraft with an unusual communications and leak infrastructure. Microsoft said DeadLock attempts privilege escalation, terminates services and processes, clears event logs, selectively encrypts files, drops ransom notes, and self-deletes, while its recovery workflow relies on a local HTML chat app, the Session messaging network, Polygon smart contracts for configuration and blog data, and Wasabi-hosted stolen files exposed through an S3-compatible browser. The company also described DeadLock's hybrid cryptography using Curve25519 and XChaCha20 with per-file ephemeral keys, assessing the scheme as cryptographically sound and leaving no practical decryption path without the attackers' private key.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.