Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300,000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates. Known victims: 402 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Lynx is a ransomware-as-a-service (RaaS) operation that emerged in mid-2024 as a rebranded version of the now-defunct INC Ransomware. The group has targeted numerous organizations across multiple sectors, leveraging its affiliate program to maximize profit through an 80/20 revenue split. Despite its relatively short operational timeline, Lynx has demonstrated significant sophistication in its attack methods and campaign management, making it a notable threat to businesses globally.

Goals & Targeting

Lynx primarily targets sectors with high financial value or sensitive data, focusing on manufacturing, business services, technology, and healthcare. The group's strategic focus is to maximize profit through efficient affiliate-driven campaigns. Target selection appears to prioritize industries where ransom demands are likely to be higher due to the critical nature of operations or valuable intellectual property. By leveraging an affiliate network, Lynx ensures geographic and sectoral diversity in its attacks, allowing it to maintain a steady flow of victims while minimizing direct operational exposure.

Enhanced Description

Lynx operates as a ransomware-as-a-service (RaaS) group that rebranded from the now-defunct INC Ransomware. Launched in mid-2024, Lynx has rapidly expanded its operations, targeting industries such as manufacturing, business services, technology, and healthcare. The group's model is centered on an affiliate system, where affiliates receive 20% of the ransom paid by victims, while the remaining 80% goes to the Lynx operators. This incentivizes affiliates to actively seek targets and negotiate ransom payments with victims. Lynx has demonstrated a preference for high-value targets in sectors with deep data repositories or critical operations, often deploying custom-tailored ransomware payloads. The group's communication infrastructure is designed to maintain operational security, using encrypted channels and anonymous payment methods such as cryptocurrency to avoid detection. With over 402 identified victims, Lynx has established itself as a formidable threat in the cybercrime landscape.

Key Capabilities

  • Spear-phishing campaigns using emails with malicious attachments or links
  • Ransomware deployment through custom-built tools tailored to target specific industries
  • Encrypted communication channels for affiliate coordination and C2 infrastructure
  • Sophisticated negotiation tactics to extract maximum ransom payments
  • Use of cryptocurrency for payment receipts and maintaining victim-anonymity

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Credential Access
Discovery

ATT&CK Techniques

T1566.002
T1078
T1059.003
T1204
T1215

Software / Tooling

Lynx Ransomware (custom)

Campaigns & Victims

Lynx has conducted numerous campaigns since its emergence, targeting businesses across the globe. The group's operational tempo is driven by affiliate activity, with a focus on maximizing victim count and ransom collection efficiency. Notable past operations include attacks on healthcare providers in late 2024, technology firms in early 2025, and business service companies throughout 2026. The group often deploys its ransomware during weekends or holidays to minimize immediate detection, leveraging time-based pressure to encourage faster ransom payment negotiations.

IOC Patterns

  • Spear-phishing emails containing attachments with malicious macros
  • Encrypted RDP connections from known Lynx C2 servers
  • Presence of specific hash-patterns in network traffic indicative of Lynx tools
  • Use of cryptocurrency wallets linked to known Lyhx ransomware transactions
  • ransom-note content demanding Bitcoin or Monero payments

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts
  • Train employees on identifying suspicious emails and links
  • Monitor for unusual network activity, particularly encrypted communications
  • Regularly back up critical systems and store backups offline
  • Enforce strong endpoint detection and response (EDR) solutions

Suggested Tags

ransomware
cybercrime
financial-gain
affiliate-program
ransomware-as-a-service

Confidence Assessment

Moderate to high confidence in Lynx's operational model and TTPs, based on affiliate network structures and observed campaign patterns. Limited visibility into the group's specific malware tools or internal communication channels creates some uncertainty in fully mapping their capabilities. Additional intelligence gaps include details on their long-term goals beyond financial gain and potential state-sponsored connections.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

User Agent 1 MD5 Hash 19

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

24

Campaigns

20

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
cybercrime
financial-gain
affiliate-program
ransomware-as-a-service

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 22, 2023
Last Seen
Aug 6, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.