Lynx Ransomware: A Rebranding of INC Ransomware


In July 2024, researchers from Palo Alto Networks discovered a successor to INC ransomware named Lynx. Since its emergence, the group behind this ransomware has actively targeted organizations in various sectors such as retail, real estate, architecture, and financial and environmental services in the U.S. and UK.

Lynx ransomware shares a significant portion of its source code with INC ransomware. INC ransomware initially surfaced in August 2023 and had variants compatible with both Windows and Linux. While we haven’t confirmed any Linux samples yet for Lynx ransomware, we have noted Windows samples. This ransomware operates using a ransomware-as-a-service (RaaS) model.

Read more…
Source: Palo Alto Unit 42


Sign up for our Newsletter


Related:

  • #StopRansomware: Play Ransomware

    December 18, 2023

    The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) are releasing this joint CSA to disseminate the Play ransomware group’s IOCs and TTPs identified through FBI investigations as recently as October 2023. Since June 2022, the Play (also known as Playcrypt) ransomware group ...

  • MongoDB, North Face owner VF Corp and Mr. Cooper fall victim to cyberattacks

    December 18, 2023

    It has been a busy few days on the cybersecurity front as three notable companies confirmed hacks over the last two days: MongoDB Inc., North Face and Vans owner VF Corp., and mortgage broker Mr. Cooper Group Inc. The first hack, that of MongoDB, was confirmed over the weekend and involved its corporate systems being breached ...

  • Israeli-linked hacker group behind major cyber-attack on Iran’s petrol stations

    December 18, 2023

    An Israeli-linked hacker group claims to have carried out a major cyber-attack on Iranian petrol stations, knocking 70 per cent of them offline on Monday. Predatory Sparrow, or “Gonjeshke Darande” in Persian, said it launched the “controlled” attack in response to “aggression” by the Islamic Republic and its proxies in the region. “This cyber attack was ...

  • Europol: Online Jihadist Propaganda – 2022 in review

    December 18, 2023

    This report is the fifth edition of the annual review of online jihadist propaganda. It analyses the major trends and developments in the propaganda of the most prominent Sunni jihadist organisations – the self-proclaimed Islamic State (IS) and al-Qaeda (AQ) – as well as their branches and offshoots. The review addresses the trajectories of these groups, ...

  • Defense Contractor Austal USA Confirms a Cyber Attack by Hunters International Ransomware Group

    December 15, 2023

    Australian-based American defense contractor Austal USA has confirmed a cyber attack after the Hunters International ransomware group listed the company and shared samples of the stolen data as proof. Austal USA is a Contractor for the US Department of Defense (DOD) and the Department of Homeland Security (DHS), undertaking major U.S. Navy shipbuilding programs. With five ...

  • Snatch ransomware attack claims probed by Kraft Heinz

    December 15, 2023

    U.S. multinational food and beverage company Kraft Heinz has launched an investigation into the Snatch ransomware gang’s recently emerged claims of an August attack even though there has been no indication of any systems compromise. Despite admitting responsibility for the attack, the Snatch ransomware operation has not posted any proof of data that it exfiltrated from ...