Skip to content

Lynx

Ransomware Group1 claimLast activity:

Overview

Lynx is a financially motivated ransomware-as-a-service operation first observed in July 2024. Palo Alto Networks Unit 42 describes it as a successor to INC Ransom and found substantial overlap between the two malware families, including 70.8% similarity among functions common to both samples it compared. That establishes a strong code lineage, but reused or purchased source code does not by itself prove that Lynx retained INC Ransom’s operators, affiliates or organizational structure.

Activity and targeting

Lynx has claimed organizations across multiple countries and industries rather than concentrating on a single target set. FortiGuard Labs found 96 organizations on the group’s leak site as of January 29, 2025, spread across 16 countries; more than 60% were in the United States, with manufacturing and construction the largest sectors in that early sample. Unit 42 also documented claims involving retail, real estate, architecture, financial services and environmental services in the United States and United Kingdom. These leak-site entries represent actor claims and should not be treated as independently verified compromises or as proof that both encryption and data theft occurred.

The operation has claimed that it excludes government institutions, hospitals and nonprofit organizations. FortiGuard nevertheless identified apparent health-care and energy organizations among the leak-site entries it reviewed, so the stated policy should be treated as criminal branding rather than a reliable targeting restriction.

Methods and operational characteristics

Lynx uses double extortion, combining file encryption with alleged data theft and threatened publication through its Tor-based leak site. Acronis Threat Research Unit reported access through stolen credentials and vulnerable VPNs in observed Lynx activity, followed by reconnaissance, privilege escalation, defense evasion, exfiltration and encryption. Because Lynx operates as a service, access methods and hands-on-keyboard tooling can vary by affiliate and should be assessed from incident-specific evidence.

Malware analysis provides stronger family-level indicators. Unit 42 and FortiGuard examined Windows samples that append the .lynx extension, support selective, partial or full encryption, can encrypt network shares, terminate processes and services, mount hidden drives, delete shadow copies and alter the desktop with a ransom notice. The encryptor can also print ransom notes to connected printers and directs victims to Tor-based communication infrastructure. FortiGuard had not identified a non-Windows Lynx variant by February 2025, even though the related INC family included Windows and ESXi versions.

What type of group is it?

Lynx is best characterized as a financially motivated RaaS and double-extortion brand. Its service model means the name may encompass malware developers, leak-site administrators, negotiators and multiple affiliates rather than one stable intrusion team. Unit 42 calls Lynx a rebranding or successor to INC Ransom, while FortiGuard describes INC as its predecessor; a March 2026 joint government advisory more cautiously notes significant TTP overlap. The reviewed evidence therefore supports a successor malware family built from INC code with high confidence, but only limited confidence in common personnel or a complete organizational rebrand. No reviewed source identifies the operators, establishes their jurisdiction or supports state sponsorship.

Incident claim

Milton ransomware incident disrupts utility billing

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

A Lynx ransomware leak-site listing published Jan. 5, 2026, identifies miltonfl.org, the City of Milton’s official domain. The date is about 10 days after Milton later said it detected suspicious activity consistent with ransomware on Dec. 26, 2025, and nearly six months before the city publicly acknowledged the incident in June.

The listing contains a significant mismatch: while the claimed victim URL is the city’s domain, the attacker-provided description refers to MILTON-FL.RESTAURANTS800.COM, a restaurant directory unrelated to municipal government. One plausible explanation is that the description was generated or summarized by an automated system, possibly a large language model, and published without human review. Copied text, faulty metadata extraction or another leak-site editorial error are also possible.

There is still medium confidence that the Lynx post refers to the same incident later disclosed by Milton because the official city domain is named, the dates closely align and the claim predates the city’s disclosure by about six months. However, Milton has not confirmed Lynx as the attacker, and DysruptionHub did not find sample files or a public tranche of allegedly stolen city data attached to the listing.

The city later said investigators found no indication city information was accessed, acquired, copied, leaked, posted publicly or otherwise taken. The Lynx entry should therefore be treated as claim-level evidence that likely corresponds to Milton’s incident, not as confirmation of the threat actor or data theft.

Impacted organizations

Impacted locations

Sources