Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300,000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates. Known victims: 402 2 ransom note(s) on file
Objectives
Executive Summary
Lynx is a ransomware-as-a-service (RaaS) operation that emerged in mid-2024 as a rebranded version of the now-defunct INC Ransomware. The group has targeted numerous organizations across multiple sectors, leveraging its affiliate program to maximize profit through an 80/20 revenue split. Despite its relatively short operational timeline, Lynx has demonstrated significant sophistication in its attack methods and campaign management, making it a notable threat to businesses globally.
Goals & Targeting
Lynx primarily targets sectors with high financial value or sensitive data, focusing on manufacturing, business services, technology, and healthcare. The group's strategic focus is to maximize profit through efficient affiliate-driven campaigns. Target selection appears to prioritize industries where ransom demands are likely to be higher due to the critical nature of operations or valuable intellectual property. By leveraging an affiliate network, Lynx ensures geographic and sectoral diversity in its attacks, allowing it to maintain a steady flow of victims while minimizing direct operational exposure.
Enhanced Description
Lynx operates as a ransomware-as-a-service (RaaS) group that rebranded from the now-defunct INC Ransomware. Launched in mid-2024, Lynx has rapidly expanded its operations, targeting industries such as manufacturing, business services, technology, and healthcare. The group's model is centered on an affiliate system, where affiliates receive 20% of the ransom paid by victims, while the remaining 80% goes to the Lynx operators. This incentivizes affiliates to actively seek targets and negotiate ransom payments with victims. Lynx has demonstrated a preference for high-value targets in sectors with deep data repositories or critical operations, often deploying custom-tailored ransomware payloads. The group's communication infrastructure is designed to maintain operational security, using encrypted channels and anonymous payment methods such as cryptocurrency to avoid detection. With over 402 identified victims, Lynx has established itself as a formidable threat in the cybercrime landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Lynx has conducted numerous campaigns since its emergence, targeting businesses across the globe. The group's operational tempo is driven by affiliate activity, with a focus on maximizing victim count and ransom collection efficiency. Notable past operations include attacks on healthcare providers in late 2024, technology firms in early 2025, and business service companies throughout 2026. The group often deploys its ransomware during weekends or holidays to minimize immediate detection, leveraging time-based pressure to encourage faster ransom payment negotiations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate to high confidence in Lynx's operational model and TTPs, based on affiliate network structures and observed campaign patterns. Limited visibility into the group's specific malware tools or internal communication channels creates some uncertainty in fully mapping their capabilities. Additional intelligence gaps include details on their long-term goals beyond financial gain and potential state-sponsored connections.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
24
Campaigns
20
IOCs
0
Observed Data
0
Tactics