lynx

First seen
2022-05-01 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-20 03:25:52
Profile updated
2026-07-07 13:17:13

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:cn country_code:ru

Context

Lynx is a remote access Trojan known for its use in cyber espionage campaigns targeting government and telecommunications sectors. It is capable of stealth operations, data exfiltration, and remote command execution.

Detection coverage

  • 2 YARA rules

Detection rules

  • SIGNATURE_BASE_MAL_RANSOM_INC_Aug24 (yara-rule)
  • MALPEDIA_Win_Lynx_Auto (yara-rule)

Reports & references

  • esentire.com — Threat Actors Deploy Sinobi Ransomware Via Compromised Sonicwall Ssl Vpn Credentials (report)
  • ransomlook.io — Lynx (report)
  • Palo Alto Unit 42 — Inc Ransomware Rebrand To Lynx (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lynx (report)
  • nextron-systems.com — In Depth Analysis Of Lynx Ransomware (report)
  • ish.com.br — Ransomware Lynx Saiba Como Mitigar Essa Ameaca (report)
  • group-ib.com — Cat S Out Of The Bag Lynx Ransomware (report)

External references