lynx
Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300, 000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates.
- Other
- Unspecified
- Healthcare
- Construction
- Business Services
- TA0001Initial Access
- TA0002Execution
- T1059.001Command and Scripting Interpreter: PowerShell
PowerShell used for payload execution and post-exploitation activity.
- TA0005Defense Evasion
- TA0006Credential Access
- T1003.001OS Credential Dumping: LSASS Memory
Credential dumping from LSASS used to facilitate lateral movement.
- TA0007Discovery
- TA0008Lateral Movement
- T1021.001Remote Services: Remote Desktop Protocol
RDP used for lateral movement with harvested credentials.
- TA0010Exfiltration
- T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage
Data exfiltrated for double extortion via the Lynx leak site prior to encryption.
- TA0011Command and Control
- T1071.001Application Layer Protocol: Web Protocols
C2 communication over HTTPS; Tor used for victim negotiation portals.
- TA0040Impact
- T1486Data Encrypted for Impact
Lynx uses AES-128 CTR mode for file encryption with RSA-2048 for key protection. Code similarities indicate it may be a rebrand or fork of INC Ransomware. Emerged mid-2024; highly aggressive targeting of SMBs and mid-market organizations across multiple sectors. Appends .lynx extension.
- T1490Inhibit System Recovery
Shadow copies deleted and recovery options disabled to prevent victim restoration.