Skip to content
The Nexus
Group profile4 claimed in last 30d12 total tracked

lynx

Forward this

Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300, 000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates.

First seen: Jun 11 · 00:00 UTCLast seen: Aug 6 · 17:21 UTCTracked since: 2024-07-29
Sectors hit
  • Other2
  • Unspecified1
  • Healthcare1
  • Construction1
  • Business Services1
Countries hit
  • United States3
  • United Kingdom2
MITRE ATT&CK · observed TTPs9 tactics

Tactics and techniques attributed to LYNX by ransomware.live's curated TTP catalog. Identifiers link to the canonical MITRE ATT&CK reference for each tactic or sub-technique.

  • TA0001Initial Access
    • T1078Valid Accounts

      Compromised credentials purchased from initial access brokers used to authenticate via RDP and VPN.

    • T1566.001Phishing: Spearphishing Attachment

      Lynx uses phishing emails with malicious attachments to deliver initial access stagers.

  • TA0002Execution
    • T1059.001Command and Scripting Interpreter: PowerShell

      PowerShell used for payload execution and post-exploitation activity.

  • TA0005Defense Evasion
    • T1036Masquerading

      Lynx ransomware binary renamed to blend into normal file system activity; masquerades as legitimate utilities.

    • T1562.001Disable or Modify Tools

      Security tools disabled before ransomware deployment.

  • TA0006Credential Access
    • T1003.001OS Credential Dumping: LSASS Memory

      Credential dumping from LSASS used to facilitate lateral movement.

  • TA0007Discovery
    • T1012Query Registry

      Registry queried to identify installed security software and system configuration before encryption.

    • T1082System Information Discovery

      Lynx queries CPU information and system details to assess the target environment and check for sandbox/analysis conditions.

  • TA0008Lateral Movement
    • T1021.001Remote Services: Remote Desktop Protocol

      RDP used for lateral movement with harvested credentials.

  • TA0010Exfiltration
    • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

      Data exfiltrated for double extortion via the Lynx leak site prior to encryption.

  • TA0011Command and Control
    • T1071.001Application Layer Protocol: Web Protocols

      C2 communication over HTTPS; Tor used for victim negotiation portals.

  • TA0040Impact
    • T1486Data Encrypted for Impact

      Lynx uses AES-128 CTR mode for file encryption with RSA-2048 for key protection. Code similarities indicate it may be a rebrand or fork of INC Ransomware. Emerged mid-2024; highly aggressive targeting of SMBs and mid-market organizations across multiple sectors. Appends .lynx extension.

    • T1490Inhibit System Recovery

      Shadow copies deleted and recovery options disabled to prevent victim restoration.

Recent claimed victims
OtherUnited StatesAug 6 · 17:26 UTC

www.jerryleigh.com

www.jerryleigh.com
OtherUnited KingdomAug 6 · 17:26 UTC

www.talbotdes.org

www.talbotdes.org
Jun 18 · 13:46 UTC

www.eastersealsia.org

Jun 18 · 10:57 UTC

www.someco.com

www.someco.com
HealthcareUnited StatesJun 18 · 10:56 UTC

www.eastersealsia.org

www.eastersealsia.org
Jun 18 · 08:44 UTC

www.wolfconstruction.net

ConstructionUnited StatesJun 18 · 05:53 UTC

www.wolfconstruction.net

www.wolfconstruction.net
Jun 11 · 18:46 UTC

www.commonwealth-partners.com

Business ServicesUnited KingdomJun 11 · 15:52 UTC

www.commonwealth-partners.com

www.commonwealth-partners.com