CARDS
CARDS
Lynx ransomware first came to public attention with documented activity on 2026-05-10, operating as a **Ransomware-as-a-Service (RaaS)** platform. Its primary motivation is financial exploitation, targeting critical infrastructure sectors, especially **energy, oil, and gas facilities**. Lynx notably evolved from the INC ransomware, evidenced by shared source code and the incorporation of enhanced encryption methods and refined attack techniques. The group's operational model is distinct, featuring a structured affiliate program that provides comprehensive resources, an intuitive dashboard, and an 80% share of ransom proceeds, while centralizing control over negotiations and ransom wallet management.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| FortiBleed Credential Exposure Campaign11,8,9,10 | FortiBleed Credential Exposure Campaign is retained in the campaign database for INC Ransom. FortiBleed is retained as a Fortinet/FortiGate credential-exposure campaign in which public reporting tied exposed or stolen Fortinet edge credentials to downstream ransomware activity involving INC Ransom and Lynx. IntelliOS treats FortiBleed as a campaign/operation context rather than proof that every exposed Fortinet environment was compromised or deployed with ransomware. |
| lynx Ransomware / Extortion Operations12 | lynx Ransomware / Extortion Operations is retained in the campaign database for lynx. Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300,000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates. |
Indicators
SOCRadar reports 767 IOCs for this profile. IntelliOS currently retains 94 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 12 source groups tracked; 11 currently contribute retained observable or context rows.
Retained Observables
Showing 60 of 94
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 31de5a766dca4eaae7b69f807ec06ae14d2ac48100e06a30e17cc9acccfd51935 | Ransomware Roundup |
| SHA-256 Hash | 3e68e5742f998c5ba34c2130b2d89ca2a6c048feb6474bc81ff000e1eaed044e5 | Ransomware Roundup |
| SHA-256 Hash | 432f549e9a2a76237133e9fe9b11fbb3d1a7e09904db5ccace29918e948529c65 | Ransomware Roundup |
| SHA-256 Hash | 468e3c2cb5b0bbc3004bbf5272f4ece5c979625f7623e6d71af5dc0929b89d6a5 | Ransomware Roundup |
| SHA-256 Hash | 4e5b9ab271a1409be300e5f3fd90f934f317116f30b40eddc82a4dfd183664125 | Ransomware Roundup |
| SHA-256 Hash | 571f5de9dd0d509ed7e5242b9b7473c2b2cbb36ba64d38b32122a0a337d6cf8b5 | Ransomware Roundup |
| SHA-256 Hash | 589ff3a5741336fa7c98dbcef4e8aecea347ea0f349b9949c6a5f6cd9d821a235 | Ransomware Roundup |
| SHA-256 Hash | 80908a51e403efd47b1d3689c3fb9447d3fb962d691d856b8b97581eefc0c4415 | Ransomware Roundup |
| SHA-256 Hash | 85699c7180ad77f2ede0b15862bb7b51ad9df0478ed394866ac7fa9362bf56835 | Ransomware Roundup |
| SHA-256 Hash | 97c8f54d70e300c7d7e973c4b211da3c64c0f1c95770f663e04e35421dfb2ba05 | Ransomware Roundup |
| SHA-256 Hash | 9a47ab27d50df1faba1dc5777bdcfff576524424bc4a3364d33267bbcf8a38965 | Ransomware Roundup |
| SHA-256 Hash | b378b7ef0f906358eec595777a50f9bb5cc7bb6635e0f031d65b818a26bdc4ee5 | Ransomware Roundup |
| SHA-256 Hash | d5ca3e0e25d768769e4afda209aca1f563768dae79571a38e3070428f8adf0315 | Ransomware Roundup |
| SHA-256 Hash | eaa0e773eb593b0046452f420b6db8a47178c09e6db0fa68f6a2d42c3f48e3bc5 | Ransomware Roundup |
| SHA-256 Hash | ecbfea3e7869166dd418f15387bc33ce46f2c72168f571071916b5054d7f6e495 | Ransomware Roundup |
| SHA-256 Hash | f71fc818362b1465fc1deb361de36badc73ac4dd9e815153c9022f82c40627875 | Ransomware Roundup |
| Filename | README.txt5 | Ransomware Roundup |
| File Extension | .LYNX5 | Ransomware Roundup |
| Tool / Process | AES-128 CTR file encryption4 | Lynx ransomware |
| Tool / Process | Claims require local validation before treating FortiBleed exposure as Lynx compromise | Retained source |
| Tool / Process | Curve25519 Donna key agreement4 | Lynx ransomware |
| Tool / Process | Desktop wallpaper replacement with ransom-note messaging6 | Threat group profile |
| Tool / Process | Double-extortion pressure with data-theft claims6 | Threat group profile |
| Tool / Process | Fast, medium, slow, and full-file encryption modes6 | Threat group profile |
| Tool / Process | FortiBleed-derived access-to-ransomware deployment context | Retained source |
| Tool / Process | FortiGate credential-harvesting campaign linkage | Retained source |
| Tool / Process | FortiGuard detections: W32/IncRansom.A!tr.ransom, W32/Filecoder_IncRansom.A!tr, W32/Filecoder_IncRansom.A!tr.ransom5 | Ransomware Roundup |
| Tool / Process | Hidden-drive loading / mount behavior5 | Ransomware Roundup |
| Tool / Process | INC Ransom source-code lineage / rebrand assessment4 | Lynx ransomware |
| Tool / Process | Initial access broker handoff context | Retained source |
| Tool / Process | Network-share encryption option5 | Ransomware Roundup |
| Tool / Process | Printer ransom-note behavior5 | Ransomware Roundup |
| Tool / Process | Process and service termination before encryption6 | Threat group profile |
| Tool / Process | Ransomware-as-a-Service affiliate model6 | Threat group profile |
| Tool / Process | Restart Manager API abuse to handle locked files5 | Ransomware Roundup |
| Tool / Process | Runtime arguments for targeted file or directory encryption5 | Ransomware Roundup |
| Tool / Process | Shadow-copy deletion5 | Ransomware Roundup |
| Tool / Process | Windows ransomware samples publicly analyzed6 | Threat group profile |
| ATT&CK ID | T1005 - Data from Local System5 | Ransomware Roundup |
| ATT&CK ID | T1039 - Data from Network Shared Drive5 | Ransomware Roundup |
| ATT&CK ID | T1059 - Command and Scripting Interpreter / operator execution context5 | Ransomware Roundup |
| ATT&CK ID | T1078 - Valid Accounts / FortiGate credential-access context | Retained source |
| ATT&CK ID | T1083 - File and Directory Discovery5 | Ransomware Roundup |
| ATT&CK ID | T1105 - Ingress Tool Transfer / affiliate intrusion context5 | Ransomware Roundup |
| ATT&CK ID | T1135 - Network Share Discovery5 | Ransomware Roundup |
| ATT&CK ID | T1190 - Exploit Public-Facing Application / edge-access context | Retained source |
| ATT&CK ID | T1486 - Data Encrypted for Impact5 | Ransomware Roundup |
| ATT&CK ID | T1489 - Service Stop5 | Ransomware Roundup |
| ATT&CK ID | T1490 - Inhibit System Recovery5 | Ransomware Roundup |
| ATT&CK ID | T1566 - Phishing / common delivery hypothesis5 | Ransomware Roundup |
| ATT&CK ID | T1567 - Exfiltration Over Web Service5 | Ransomware Roundup |
| ATT&CK ID | T1657 - Financial Theft / extortion pressure context5 | Ransomware Roundup |
| Alias / Related Name | FortiBleed-linked ransomware operation | Retained source |
| Alias / Related Name | INC / Lynx2 | SOCRadar |
| Alias / Related Name | INC Ransom lineage2 | SOCRadar |
| Alias / Related Name | Lynx2 | SOCRadar |
| Alias / Related Name | Lynx ransomware2 | SOCRadar |
| Alias / Related Name | Tarnished Scorpius lineage context4 | Lynx ransomware |
| Malware Family | INC Ransom lineage / predecessor context5 | Ransomware Roundup |
| Malware Family | Lynx ransomware4 | Lynx ransomware |
| Campaign Context | January 2025: Fortinet reported 96 data-leak-site victim entries and geographic/sector concentration caveats; IntelliOS does not republish raw victim lists.5 | Ransomware Roundup |
| Campaign Context | July 2024: WatchGuard, Fortinet, Unit 42, and Halcyon place Lynx emergence/first-seen activity in July 2024.3 | WatchGuard ransomware tracker |
| Campaign Context | July 2026: SOCRadar linked FortiBleed credential-harvesting infrastructure to INC Ransom and Lynx ransomware operations. | Retained source |
| CLASSIFICATION | SOCRadar and WatchGuard retain Lynx as an active crypto-ransomware/data-broker/RaaS actor with July 2024 first-seen context.3 | WatchGuard ransomware tracker |
| COUNTRY | Australia3 | WatchGuard ransomware tracker |
| COUNTRY | Canada3 | WatchGuard ransomware tracker |
| COUNTRY | Guatemala3 | WatchGuard ransomware tracker |
| COUNTRY | United Kingdom3 | WatchGuard ransomware tracker |
| COUNTRY | United States3 | WatchGuard ransomware tracker |
| OBSERVABLE | Cybersecurity Dive independently summarized SOCRadar's FortiBleed-to-INC/Lynx reporting and retained caveats that some Nextcloud exploitation questions remained under investigation.9 | FortiBleed campaign traced to INC and Lynx ransomware operations |
| OBSERVABLE | Fortinet retained public SHA-256 file hashes for Lynx ransomware samples; IntelliOS retains hashes but excludes raw contact channels, onion URLs, victim rows, negotiation details, and payment instructions.5 | Ransomware Roundup |
| OBSERVABLE | Picus and Halcyon describe Lynx as a RaaS actor tied to INC Ransom source-code lineage and double-extortion operations; IntelliOS uses those as enrichment context.7 | Lynx ransomware |
| OBSERVABLE | SOCRadar says FortiBleed infrastructure linked to INC and Lynx included an operator observed in both negotiation panels and at least 12 ransomware deployments from FortiBleed-derived access. | Retained source |
| OBSERVABLE | The Hacker News summarized SOCRadar's FortiBleed findings, including FortiGate scanning, admin-level access, completed attack-chain counts, and ransomware deployments; IntelliOS treats this as corroborating coverage, not a separate primary attribution source.10 | FortiBleed credential theft linked to INC and Lynx ransomware |
| OBSERVABLE | Unit 42 reported 70.8% matched functions between analyzed INC and Lynx samples, supporting source-code lineage but not proving every INC operator is Lynx.4 | Lynx ransomware |
| REGION | Global exposure3 | WatchGuard ransomware tracker |
| SECTOR | Aerospace3 | WatchGuard ransomware tracker |
| SECTOR | Agriculture3 | WatchGuard ransomware tracker |
| SECTOR | Automotive3 | WatchGuard ransomware tracker |
| SECTOR | Construction3 | WatchGuard ransomware tracker |
| SECTOR | Engineering services3 | WatchGuard ransomware tracker |
| SECTOR | Environmental services3 | WatchGuard ransomware tracker |
| SECTOR | Finance3 | WatchGuard ransomware tracker |
| SECTOR | Healthcare3 | WatchGuard ransomware tracker |
| SECTOR | Hospitality3 | WatchGuard ransomware tracker |
| SECTOR | Manufacturing3 | WatchGuard ransomware tracker |
| SECTOR | Mining3 | WatchGuard ransomware tracker |
| SECTOR | Oil and gas3 | WatchGuard ransomware tracker |
| SECTOR | Organizations with exposed or compromised Fortinet edge credentials | Retained source |
| SECTOR | Real estate3 | WatchGuard ransomware tracker |
| SECTOR | Retail3 | WatchGuard ransomware tracker |
| SECTOR | Technology3 | WatchGuard ransomware tracker |
| SOURCE_BOUNDARY | Recorded Future/Insikt treats FortiBleed seller credibility as mixed and does not independently validate every downstream actor claim; IntelliOS keeps FortiBleed-to-Lynx claims source-caveated.8 | FortiBleed campaign exposes credentials for FortiGate systems |
| SOURCE_BOUNDARY | Unit 42 and Fortinet assess Lynx as sharing significant code and behavior overlap with INC Ransom; IntelliOS records lineage/context rather than automatically merging Lynx and INC into one actor card.4 | Lynx ransomware |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 767 | 4 | Reported IOC count and SOCRadar-backed observable rows retained in IntelliOS. |
| SOCRadar1 | N/A | 0 | Context source retained; no direct observable rows retained from this source yet. |
| SOCRadar2 | N/A | 4 | Public observables or source-context rows retained and displayed. |
| WatchGuard3 | N/A | 23 | Public observables or source-context rows retained and displayed. |
| Palo Alto Networks Unit 424 | N/A | 7 | Public observables or source-context rows retained and displayed. |
| Fortinet FortiGuard Labs5 | N/A | 40 | Public observables or source-context rows retained and displayed. |
| Halcyon6 | N/A | 6 | Public observables or source-context rows retained and displayed. |
| Picus Security7 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| SOCRadar STRU | N/A | 10 | Public observables or source-context rows retained and displayed. |
| Recorded Future Insikt Group8 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| Cybersecurity Dive9 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| The Hacker News10 | N/A | 1 | Public observables or source-context rows retained and displayed. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Lynx | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Lynx | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/lynx | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | WatchGuard ransomware tracker: Lynx https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/lynx | Ransomware Tracker |
| 4 | Lynx ransomware: a rebranding of INC ransomware https://unit42.paloaltonetworks.com/inc-ransomware-rebrand-to-lynx/ | Malware Analysis |
| 5 | Ransomware Roundup: Lynx https://www.fortinet.com/blog/threat-research/ransomware-roundup-lynx | Malware Analysis / IOCs |
| 6 | Threat group profile: Lynx https://www.halcyon.ai/threat-group/lynx | Threat Actor Profile |
| 7 | Lynx ransomware: exposing how INC ransomware rebrands itself https://www.picussecurity.com/resource/blog/lynx-ransomware | Ransomware Analysis |
| 8 | FortiBleed campaign exposes credentials for FortiGate systems https://www.recordedfuture.com/blog/critical-fortibleed-campaign | Campaign Deconfliction |
| 9 | FortiBleed campaign traced to INC and Lynx ransomware operations https://www.cybersecuritydive.com/news/fortibleed-campaign-traced-to-inc-and-lynx-ransomware-operations/824348/ | News / Attribution Coverage |
| 10 | FortiBleed credential theft linked to INC and Lynx ransomware https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html | News / Attribution Coverage |
| 11 | FortiBleed campaign linked to INC and Lynx ransomware operations https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/ | SOCRadar campaign row source for FortiBleed Credential Exposure Campaign. |
| 12 | lynx - Ransomware.live group profile https://www.ransomware.live/group/lynx | Ransomware.live campaign row source for lynx Ransomware / Extortion Operations. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Lynx.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |