Lynx Ransomware Pouncing on Utilities
ID: 8f9ad7ae-f658-547c-a481-0976c1691e8e
STIX ID: report--8f9ad7ae-f658-547c-a481-0976c1691e8e
Feed Name: CISecurity.org Insights Blog
CIS CTI highlights an active 2024 ransomware threat from the Lynx group targeting U.S. utilities (energy, oil, gas), exploiting known vulnerabilities and phishing to gain access, terminating security and backup processes, deleting shadow copies, encrypting local and network data, and coercing victims via double extortion and public leak sites; the report includes associated URLs and SHA-256 IOCs and recommends defense-in-depth with CIS Controls, continuous vulnerability management, email/web protections, ICS-focused guidance, and CISA’s #StopRansomware resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
