Description
Lynx is a Ransomware-as-a-Service operation that became publicly visible during 2024. Threat-intelligence reporting has identified strong technical and operational similarities between Lynx and INC Ransom, including similarities in malware functionality and infrastructure.
The group operates through an affiliate-based model in which external operators conduct intrusions while the core operation provides ransomware infrastructure and supporting services.
The model allows Lynx to scale attacks across different organisations without requiring a single threat actor to conduct every stage of an intrusion.
Technical Description
Lynx ransomware supports attacks against multiple environments, including Windows systems and Linux/VMware ESXi infrastructure.
Once attackers establish access, they can perform network reconnaissance, identify valuable systems and shared resources, move laterally, disable security or backup-related processes, and prepare systems for encryption.
The ransomware uses AES-128 for file encryption, while Curve25519 is used to protect the encryption key. Encrypted files can receive the .LYNX extension.
The operation also employs double extortion. Before or during encryption, attackers may collect sensitive information and subsequently threaten to release the stolen material through their leak infrastructure.
Attack Overview
A typical Lynx intrusion can be represented as the following sequence:
Initial Access → Credential/Network Discovery → Privilege Escalation → Lateral Movement → Defense Evasion → Data Exfiltration → Encryption → Extortion
1. Initial Access
Affiliates may obtain access through phishing, compromised credentials, exposed remote services, or exploitation of vulnerable internet-facing applications.
2. Environment Discovery
After entering the environment, attackers conduct reconnaissance to identify systems, network shares, valuable assets, and potential paths for lateral movement.
3. Privilege Escalation
Compromised or stolen accounts may be used to obtain additional privileges and expand access within the environment.
4. Lateral Movement
SMB and other Windows networking mechanisms can be used to move between systems and reach additional endpoints and servers.
5. Defense Evasion
Before encryption, attackers may attempt to disable endpoint-security products, backup services, database services, and other processes that could interfere with the ransomware operation.
6. Data Theft
Sensitive information may be collected and transferred outside the victim environment, establishing leverage for the subsequent extortion phase.
7. Encryption
The ransomware encrypts files across accessible systems. Virtualisation infrastructure can also be targeted, increasing the potential impact on enterprise workloads.
8. Extortion
Victims receive ransom instructions and may be threatened with publication of stolen information if payment requirements are not satisfied.
Technical Analysis
One of Lynx's important characteristics is its focus on operational efficiency rather than simply introducing a novel encryption mechanism.
The ransomware uses multi-threaded encryption to process large numbers of files efficiently. AES-128 is used for the underlying file encryption, while Curve25519 protects the corresponding encryption key.
A distinctive host-level indicator is the .LYNX extension appended to encrypted files.
The malware can also interfere with recovery mechanisms by deleting Volume Shadow Copies and disabling recovery-related functionality. This increases the likelihood that victims will need to rely on independent backups.
Another notable behaviour is the termination of security and infrastructure-related processes before encryption. This can include endpoint-security software, databases, mail infrastructure, and backup agents.
Lynx has also demonstrated an unusual psychological-pressure technique: ransom messages may be sent to network-connected printers, causing the demand to be physically printed throughout an organisation.
| IOC Type | Value | Notes |
|---|---|---|
| File Extension | .LYNX | Extension observed on files encrypted by Lynx ransomware |
| File Name | README.txt | Ransom note dropped in affected directories |
| File Name | background-image.jpg | Wallpaper artifact associated with the ransomware |
| File Name | folder.ico | Dropped icon artifact |
| File Name | pictures.ico | Dropped icon artifact |
| Registry Key | HKCU\Control Panel\Desktop\Wallpaper | Registry value associated with wallpaper modification |
| File Path | C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ | Reported location for dropped icon artifacts |
| Command | vssadmin | Associated with Volume Shadow Copy deletion |
| Hash (SHA-256) | 31de5a766dca4eaae7b69f807ec06ae14d2ac48100e06a30e17cc9acccfd519 | Reported Lynx ransomware sample |
| Hash (SHA-256) | 3e68e5742f998c5ba34c2130b2d89ca2a6c048feb6474bc81ff000e1eaed044 | Reported Lynx ransomware sample |
| Hash (SHA-256) | 468e3c2cb5b0bbc3004bbf5272f4ece5c979625f7623e6d71af5dc0929b89d6 | Reported Lynx ransomware sample |
| Hash (SHA-256) | 4e5b9ab271a1409be300e5f3fd90f934f317116f30b40eddc82a4dfd1836641 | Reported Lynx ransomware sample |
| Hash (SHA-256) | 571f5de9dd0d509ed7e5242b9b7473c2b2cbb36ba64d38b32122a0a337d6cf8b | Reported Lynx ransomware sample |
| Hash (SHA-256) | 589ff3a5741336fa7c98dbcef4e8aecea347ea0f349b9949c6a5f6cd9d821a2 | Reported Lynx ransomware sample |
Potential Impact
A successful Lynx intrusion can produce consequences beyond simple file encryption.
Operational Disruption
Encryption of endpoints, servers, and virtualisation infrastructure can interrupt critical business applications and internal services.
Data Exposure
When attackers combine data theft with encryption, organisations face both availability and confidentiality risks.
Recovery Costs
Organisations may incur significant costs associated with incident response, forensic investigation, infrastructure rebuilding, legal requirements, regulatory notifications, and business interruption.
Reputational Damage
Publication of stolen information or prolonged service disruption can affect customer confidence, business relationships, and organisational reputation.
Critical Infrastructure Risk
The Electrica incident demonstrates that ransomware affecting corporate IT can create serious concerns for critical-infrastructure organisations. In that case, segmentation between corporate IT and operational systems helped prevent the incident from disrupting electricity distribution.
Recommendations
Immediate Actions
1. Isolate Suspected Systems
Immediately isolate confirmed or suspected infected hosts from the network to prevent further lateral movement.
2. Protect Backup Infrastructure
Disconnect or isolate backup systems that may still be accessible from compromised accounts or hosts.
3. Preserve Evidence
Avoid unnecessary system changes or reboots where possible. Preserve relevant endpoint, authentication, network, and security logs for forensic investigation.
4. Investigate Credential Compromise
Identify potentially compromised accounts and reset credentials after determining the scope of attacker access.
5. Search for Ransomware Indicators
Hunt for .LYNX files, README.txt, Shadow Copy deletion activity, suspicious process termination, and abnormal printer activity.
6. Determine Data Exposure
Investigate whether sensitive information was staged or transferred outside the environment before encryption.
7. Coordinate Incident Response
Engage the organisation's incident-response, legal, security, and relevant regulatory or national cybersecurity teams as appropriate.
Preventive Actions
1. Enforce MFA
Enable multi-factor authentication for VPN, RDP, administrative accounts, and other externally accessible services.
2. Secure Remote Access
Restrict exposed RDP services and continuously monitor authentication activity for brute-force attempts or unusual access patterns.
3. Patch Internet-Facing Systems
Prioritise remediation of vulnerabilities affecting externally exposed applications and infrastructure.
4. Implement Network Segmentation
Separate corporate IT networks from OT, ICS, and SCADA environments. Restrict unnecessary communication between network zones.
5. Deploy EDR
Use behavioural detection capable of identifying mass file modifications, abnormal process termination, recovery-mechanism deletion, and suspicious administrative activity.
6. Maintain Immutable Backups
Maintain offline, isolated, or immutable backup copies and regularly test restoration procedures.
7. Apply Least Privilege
Reduce unnecessary administrative privileges and monitor the use of privileged or valid accounts.
8. Improve Phishing Resistance
Combine email security controls with regular security-awareness training and phishing simulations.
9. Monitor Lateral Movement
Monitor SMB activity, network-share enumeration, unusual internal scanning, and abnormal authentication patterns.
The supplied case study similarly prioritises patch management, MFA, email security, segmentation, least privilege, EDR, and resilient backups as key defensive controls.
Conclusion
Lynx demonstrates how the Ransomware-as-a-Service model continues to evolve. The operation combines an established ransomware codebase with an affiliate-driven structure, multi-platform tooling, aggressive extortion techniques, and capabilities designed to disrupt both production systems and recovery mechanisms.
For defenders, the most important lesson is that ransomware prevention cannot depend on detecting the final encryption stage alone. Organisations should focus on the earlier stages of the intrusion, including exposed services, credential abuse, lateral movement, privilege escalation, and attempts to disable security controls.
Strong MFA, timely patching, network segmentation, endpoint monitoring, least-privilege access, and tested offline or immutable backups remain critical safeguards.
The Electrica case further highlights the value of separating corporate IT from operational technology. Effective segmentation, rapid containment, and coordinated incident response can significantly limit the consequences of a ransomware intrusion, even when an attacker successfully compromises part of the enterprise environment.