Financially motivated ransomware-as-a-service (RaaS) operation; not attributed to a nation-state. Widely assessed by Palo Alto Unit 42, Rapid7, Nextron Systems and Group-IB as a rebrand/successor of the INC Ransom operation, built on purchased or repurposed INC source code. Operators are believed to be Russian-speaking (advertised on the RAMP forum; CIS nations are excluded from targeting), but no confirmed real-world identities are public.
First seen
2024-07
Last active
2026-08
Motivation
Financial gain via double extortion (data theft plus encryption) under a RaaS affiliate model.
Attribution confidence
medium
MENA targeting
Saudi Arabia, UAE
Sectors
Technology, retail
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, UAE (Technology, retail sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Lynx binary enumerates network shares via WNetOpenEnumW/WNetEnumResourceW (RESOURCE_GLOBALNET) for --encrypt-network; affiliates also enumerated shares with NetScan (Nextron, DFIR Report).
Affiliate deployed SoftPerfect NetScan v7.2.7 configured for full IP-range scanning and share enumeration, plus NetExec SMB enumeration (The DFIR Report).
Useful?
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.
Archives uploaded to temp.sh via browser as the double-extortion step; Lynx DLS (lynxblog) publishes stolen data of non-payers (DFIR Report, Group-IB, Unit 42).
Enumerates services via OpenSCManagerW and stops/terminates those matching sql, veeam, backup, exchange, java; uses Restart Manager API to release file handles (Nextron, Unit 42).
Drops background-image.jpg ransom note and sets it as desktop wallpaper via registry; also prints the ransom note to every attached printer via EnumPrintersW/WritePrinter (Nextron, Unit 42).
The DFIR Report (Dec 2025) Lynx intrusion began with a successful RDP logon using pre-compromised credentials, no brute force or credential stuffing observed (IAB/infostealer sourced).
RDP from the beachhead to domain controllers, hypervisors, backup and file servers using compromised domain-admin and look-alike accounts (The DFIR Report).
Lynx enables SeTakeOwnershipPrivilege via OpenProcessToken/LookupPrivilegeValueW/AdjustTokenPrivileges before touching protected files (Nextron, Group-IB).
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Lynx's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 6 techniques
Advanced Anti-Phishing T1566partialAnti-SpoofingT1566significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1567partialConditional AccessT1078minimalIdentity Secure ScoreT1078minimalMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1566partialPrivileged Identity ManagementT1078minimalPrivileged Identity ManagementT1136partialPassword PolicyT1078significantPassword ProtectionT1078partialRole Based Access ControlT1059minimalRole Based Access ControlT1078minimalRole Based Access ControlT1136minimalAntimalwareT1059significantAntimalwareT1566significantAnti-PhishingT1566significantAntiSpamT1566significantAudit SolutionsT1078partialInformation ProtectionT1567significant
detect · 10 techniques
Advanced Anti-Phishing T1566partialApp GovernanceT1078significantApp GovernanceT1566significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1133partialDefender for Cloud AppsT1486partialDefender for Cloud AppsT1567partialMicrosoft Defender for IdentityT1021minimalMicrosoft Defender for IdentityT1059minimalMicrosoft Defender for IdentityT1133minimalLateral Movements
respond · 5 techniques
Advanced Anti-Phishing T1566partialAutomated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1567significantIncident ResponseT1059minimalIncident ResponseT1078minimalIncident ResponseT1136minimalIncident ResponseT1566minimalQuarantine PoliciesT1566significantSafe AttachmentsT1566significantATT&CK Simulation TrainingT1566partialZero Hour Auto PurgeT1059significantZero Hour Auto PurgeT1566significantConditional Access
Countermeasures · D3FEND
Defensive techniques that counter Lynx's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.