ThreatBeaconXThreatBeaconXSubscribe
HighRansomware · 7 min read

Lynx Ransomware: Inside the RaaS Operation Behind a Growing Wave of Enterprise Attacks

Lynx is a ransomware-as-a-service (RaaS) operation that emerged in 2024 and has been linked by multiple threat-intelligence researchers to the earlier INC Ransom operation. Rather than relying solely on new malware development, the operation appears to have built upon an existing ransomware codebase while expanding its affiliate infrastructure and operational capabilities. Lynx affiliates have targeted organisations across multiple industries and regions, using techniques including credential-based access, exploitation of exposed services, network discovery, lateral movement, security-tool disruption, data theft, and large-scale encryption. The operation is particularly notable for its double-extortion approach. Victims may face both operational disruption from encryption and the threat of sensitive information being published if ransom demands are not met. A documented attack against Romanian electricity company Electrica also demonstrates the importance of network segmentation. Although corporate IT systems were impacted, separation between IT and operational technology environments helped prevent disruption to the underlying electricity-distribution infrastructure.

Written by Lakshmi Koumudi·Published Sep 3, 2026

Description

Lynx is a Ransomware-as-a-Service operation that became publicly visible during 2024. Threat-intelligence reporting has identified strong technical and operational similarities between Lynx and INC Ransom, including similarities in malware functionality and infrastructure.

The group operates through an affiliate-based model in which external operators conduct intrusions while the core operation provides ransomware infrastructure and supporting services.

The model allows Lynx to scale attacks across different organisations without requiring a single threat actor to conduct every stage of an intrusion.

Technical Description

Lynx ransomware supports attacks against multiple environments, including Windows systems and Linux/VMware ESXi infrastructure.

Once attackers establish access, they can perform network reconnaissance, identify valuable systems and shared resources, move laterally, disable security or backup-related processes, and prepare systems for encryption.

The ransomware uses AES-128 for file encryption, while Curve25519 is used to protect the encryption key. Encrypted files can receive the .LYNX extension.

The operation also employs double extortion. Before or during encryption, attackers may collect sensitive information and subsequently threaten to release the stolen material through their leak infrastructure.

Attack Overview

A typical Lynx intrusion can be represented as the following sequence:

Initial Access → Credential/Network Discovery → Privilege Escalation → Lateral Movement → Defense Evasion → Data Exfiltration → Encryption → Extortion

1. Initial Access

Affiliates may obtain access through phishing, compromised credentials, exposed remote services, or exploitation of vulnerable internet-facing applications.

2. Environment Discovery

After entering the environment, attackers conduct reconnaissance to identify systems, network shares, valuable assets, and potential paths for lateral movement.

3. Privilege Escalation

Compromised or stolen accounts may be used to obtain additional privileges and expand access within the environment.

4. Lateral Movement

SMB and other Windows networking mechanisms can be used to move between systems and reach additional endpoints and servers.

5. Defense Evasion

Before encryption, attackers may attempt to disable endpoint-security products, backup services, database services, and other processes that could interfere with the ransomware operation.

6. Data Theft

Sensitive information may be collected and transferred outside the victim environment, establishing leverage for the subsequent extortion phase.

7. Encryption

The ransomware encrypts files across accessible systems. Virtualisation infrastructure can also be targeted, increasing the potential impact on enterprise workloads.

8. Extortion

Victims receive ransom instructions and may be threatened with publication of stolen information if payment requirements are not satisfied.

Technical Analysis

One of Lynx's important characteristics is its focus on operational efficiency rather than simply introducing a novel encryption mechanism.

The ransomware uses multi-threaded encryption to process large numbers of files efficiently. AES-128 is used for the underlying file encryption, while Curve25519 protects the corresponding encryption key.

A distinctive host-level indicator is the .LYNX extension appended to encrypted files.

The malware can also interfere with recovery mechanisms by deleting Volume Shadow Copies and disabling recovery-related functionality. This increases the likelihood that victims will need to rely on independent backups.

Another notable behaviour is the termination of security and infrastructure-related processes before encryption. This can include endpoint-security software, databases, mail infrastructure, and backup agents.

Lynx has also demonstrated an unusual psychological-pressure technique: ransom messages may be sent to network-connected printers, causing the demand to be physically printed throughout an organisation.


IOC TypeValueNotes
File Extension.LYNXExtension observed on files encrypted by Lynx ransomware
File NameREADME.txtRansom note dropped in affected directories
File Namebackground-image.jpgWallpaper artifact associated with the ransomware
File Namefolder.icoDropped icon artifact
File Namepictures.icoDropped icon artifact
Registry KeyHKCU\Control Panel\Desktop\WallpaperRegistry value associated with wallpaper modification
File PathC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\Reported location for dropped icon artifacts
CommandvssadminAssociated with Volume Shadow Copy deletion
Hash (SHA-256)31de5a766dca4eaae7b69f807ec06ae14d2ac48100e06a30e17cc9acccfd519Reported Lynx ransomware sample
Hash (SHA-256)3e68e5742f998c5ba34c2130b2d89ca2a6c048feb6474bc81ff000e1eaed044Reported Lynx ransomware sample
Hash (SHA-256)468e3c2cb5b0bbc3004bbf5272f4ece5c979625f7623e6d71af5dc0929b89d6Reported Lynx ransomware sample
Hash (SHA-256)4e5b9ab271a1409be300e5f3fd90f934f317116f30b40eddc82a4dfd1836641Reported Lynx ransomware sample
Hash (SHA-256)571f5de9dd0d509ed7e5242b9b7473c2b2cbb36ba64d38b32122a0a337d6cf8bReported Lynx ransomware sample
Hash (SHA-256)589ff3a5741336fa7c98dbcef4e8aecea347ea0f349b9949c6a5f6cd9d821a2Reported Lynx ransomware sample

Potential Impact

A successful Lynx intrusion can produce consequences beyond simple file encryption.

Operational Disruption

Encryption of endpoints, servers, and virtualisation infrastructure can interrupt critical business applications and internal services.

Data Exposure

When attackers combine data theft with encryption, organisations face both availability and confidentiality risks.

Recovery Costs

Organisations may incur significant costs associated with incident response, forensic investigation, infrastructure rebuilding, legal requirements, regulatory notifications, and business interruption.

Reputational Damage

Publication of stolen information or prolonged service disruption can affect customer confidence, business relationships, and organisational reputation.

Critical Infrastructure Risk

The Electrica incident demonstrates that ransomware affecting corporate IT can create serious concerns for critical-infrastructure organisations. In that case, segmentation between corporate IT and operational systems helped prevent the incident from disrupting electricity distribution.

Recommendations

Immediate Actions

1. Isolate Suspected Systems

Immediately isolate confirmed or suspected infected hosts from the network to prevent further lateral movement.

2. Protect Backup Infrastructure

Disconnect or isolate backup systems that may still be accessible from compromised accounts or hosts.

3. Preserve Evidence

Avoid unnecessary system changes or reboots where possible. Preserve relevant endpoint, authentication, network, and security logs for forensic investigation.

4. Investigate Credential Compromise

Identify potentially compromised accounts and reset credentials after determining the scope of attacker access.

5. Search for Ransomware Indicators

Hunt for .LYNX files, README.txt, Shadow Copy deletion activity, suspicious process termination, and abnormal printer activity.

6. Determine Data Exposure

Investigate whether sensitive information was staged or transferred outside the environment before encryption.

7. Coordinate Incident Response

Engage the organisation's incident-response, legal, security, and relevant regulatory or national cybersecurity teams as appropriate.

Preventive Actions

1. Enforce MFA

Enable multi-factor authentication for VPN, RDP, administrative accounts, and other externally accessible services.

2. Secure Remote Access

Restrict exposed RDP services and continuously monitor authentication activity for brute-force attempts or unusual access patterns.

3. Patch Internet-Facing Systems

Prioritise remediation of vulnerabilities affecting externally exposed applications and infrastructure.

4. Implement Network Segmentation

Separate corporate IT networks from OT, ICS, and SCADA environments. Restrict unnecessary communication between network zones.

5. Deploy EDR

Use behavioural detection capable of identifying mass file modifications, abnormal process termination, recovery-mechanism deletion, and suspicious administrative activity.

6. Maintain Immutable Backups

Maintain offline, isolated, or immutable backup copies and regularly test restoration procedures.

7. Apply Least Privilege

Reduce unnecessary administrative privileges and monitor the use of privileged or valid accounts.

8. Improve Phishing Resistance

Combine email security controls with regular security-awareness training and phishing simulations.

9. Monitor Lateral Movement

Monitor SMB activity, network-share enumeration, unusual internal scanning, and abnormal authentication patterns.

The supplied case study similarly prioritises patch management, MFA, email security, segmentation, least privilege, EDR, and resilient backups as key defensive controls.

Conclusion

Lynx demonstrates how the Ransomware-as-a-Service model continues to evolve. The operation combines an established ransomware codebase with an affiliate-driven structure, multi-platform tooling, aggressive extortion techniques, and capabilities designed to disrupt both production systems and recovery mechanisms.

For defenders, the most important lesson is that ransomware prevention cannot depend on detecting the final encryption stage alone. Organisations should focus on the earlier stages of the intrusion, including exposed services, credential abuse, lateral movement, privilege escalation, and attempts to disable security controls.

Strong MFA, timely patching, network segmentation, endpoint monitoring, least-privilege access, and tested offline or immutable backups remain critical safeguards.

The Electrica case further highlights the value of separating corporate IT from operational technology. Effective segmentation, rapid containment, and coordinated incident response can significantly limit the consequences of a ransomware intrusion, even when an attacker successfully compromises part of the enterprise environment.



MITRE ATT&CK Mapping

T1486 — Data Encrypted for Impact