logo

Cat’s Got Your Files: Lynx Ransomware

ID: 2b88ed65-9798-5713-b698-f5304e29c8f1

STIX ID: report--2b88ed65-9798-5713-b698-f5304e29c8f1

Feed Name: The DFIR Report

Threat Score
78/100

Date Published: 2025-11-17

Date Updated: 2026-04-19

Author: editor

...
...

- A DFIR report documents a nine-day intrusion that began with successful RDP using valid credentials, escalated to domain controller access where look‑alike privileged accounts and AnyDesk were installed for persistence, used SoftPerfect NetScan and NetExec for discovery and lateral movement, exfiltrated compressed archives to temp.sh, deleted Veeam backups, and ultimately deployed Lynx ransomware across backup and file servers (Time to Ransomware ≈ 178 hours). The report provides IOCs (IPs, file hashes), command artifacts, TTP mappings to ATT&CK, and detection resources (Sigma/YARA) to support containment and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.