Lynx

Lynx — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

LynxConfidence: High

Ransomware (RaaS)

Motivation: Financial

1Attributed Breaches
HighAttribution Confidence
Ransomware (RaaS)Actor Type

Overview

Widely assessed by Unit 42 as a rebrand of the INC ransomware operation, appearing mid-2024 with ~300 victims across retail, real estate, architecture, financial, and environmental services in the US and UK. Provides affiliates encryption tooling, leak-site access, and support.

Tactics, Targeting & TTPs

Provides affiliates encryption tooling, leak-site access and support. Rebrand of INC Ransom per Unit 42. See [[breach-record-generation]] for INC lineage.

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation