Lynx Ransomware: A Rebranding of INC Ransomware
ID: e81a6b52-7093-55b2-a359-b67dde72c155
STIX ID: report--e81a6b52-7093-55b2-a359-b67dde72c155
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-10-10
Date Updated: 2026-04-28
Author: Pranay Kumar Chhaparwal, Micah Yates and Benjamin Chang
**Executive summary:** Palo Alto Networks Unit42 reports on Lynx ransomware, a successor to INC ransomware used in active double-extortion campaigns against organizations in retail, real estate, architecture, financial and environmental services in the U.S. and UK; the report includes technical analysis (Windows samples using AES-128-CTR and Curve25519, .lynx file extension, process termination, shadow copy deletion, use of Restart Manager, OneNote reporting), operational details (RaaS model, phishing/malicious downloads, public Tor leak sites), and multiple IoCs (SHA256 hashes, contact email, Tor URLs) to support detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
