Ransomware
Lynx RansomwareINC Ransom successorINC rebrand
Attribution
Financially motivated ransomware-as-a-service (RaaS) operation; not attributed to a nation-state. Widely assessed by Palo Alto Unit 42, Rapid7, Nextron Systems and Group-IB as a rebrand/successor of the INC Ransom operation, built on purchased or repurposed INC source code. Operators are believed to be Russian-speaking (advertised on the RAMP forum; CIS nations are excluded from targeting), but no confirmed real-world identities are public.
Motivation
Financial gain via double extortion (data theft plus encryption) under a RaaS affiliate model.
Attribution confidence
medium
MENA targeting
Saudi Arabia, UAE
Sectors
Technology, retail
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, UAE (Technology, retail sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.