Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Lynx is a financially motivated ransomware-as-a-service operation that emerged in mid-2024 and is widely assessed to be a rebrand/successor of the INC Ransom gang, reusing purchased or derived INC source code. It runs a professionalized affiliate program advertised on the RAMP cybercrime forum, offering affiliates an 80/20 revenue split, and employs double extortion with clear-web and Tor leak sites. As of mid-to-late 2026 Lynx remains active, having claimed 400+ victims concentrated in the United States and other Western economies across manufacturing, professional services, technology, retail and real estate.
Lynx first surfaced in July 2024 and was quickly connected to the earlier INC Ransom operation, which itself had appeared in August 2023. INC's source code was reported for sale on criminal underground markets as early as March 2024, and Lynx is assessed to have acquired or repurposed that code. Multiple independent researchers corroborated the lineage through binary-diff analysis: Palo Alto Networks Unit 42 (report published October 10, 2024) and Rapid7 found roughly 48% overall function overlap and 70.8% similarity across shared functions between the Windows encryptors, while Group-IB's analysis of the Linux/ESXi variant found approximately 87% overall and 91% functional similarity to INC's Linux malware. Note that public reporting on the exact code-overlap figures varies by source and by which binaries were compared; some secondary write-ups cite a higher ~90% figure, so the specific percentages should be treated as sample-dependent rather than a single authoritative number.
Operationally, Lynx is a structured RaaS. A recruiter using the handle "silencer" advertised the affiliate program on the RAMP forum on August 8, 2024, offering an 80/20 split in the affiliate's favor plus optional paid "call service" pressure operations. Group-IB obtained access to the affiliate panel and documented its structure (News, Companies, Chats, Stuffers/sub-affiliates, and Leaks sections) and configurable encryption modes (fast 5%, medium 15%, slow 25%, and entire 100%). Lynx uses classic double extortion: data is exfiltrated before encryption, victims are named on clear-web and Tor leak sites, and stolen data is published or sold if the ransom is unpaid. The group publicly claims it avoids governmental organizations, hospitals, healthcare, churches, children's charities and CIS nations, though such "codes of conduct" are self-declared and unverifiable.
Victimology is deliberate and Western-enterprise-focused rather than opportunistic-only. Victim counts grew steadily from ~20 shortly after emergence to nearly 300 by August 2025 and to 400+ by mid-to-late 2026 (ransomware.live tracked ~417 claimed victims spanning 48 countries as of early September 2026, with last observed leak-site activity in late August 2026). The heaviest concentrations are the United States (the large majority), followed by the United Kingdom, Canada, Germany and Australia, with leading sectors being manufacturing, professional services and technology.
+25 more relationships — see the relationships browser.
MENA relevance: MENA exposure is minimal and evidentiary confidence is LOW — the current RaqibCTI Saudi Arabia and UAE country tags reflect a small number of unverified leak-site/aggregator claims rather than independently confirmed targeting, so the tags are best treated as MIXED (a listing exists, but confirmation does not); ransomware.live attributes roughly one UAE listing ("secure.ae", ~February 2026) and one Saudi listing ("Diyar", ~June 2025) to Lynx, and Darktrace has noted Lynx incidents touching energy and retail organizations in the Middle East, but none of these MENA claims are corroborated by primary incident-response reporting and should not be presented as confirmed until validated.