lynx
- First seen
- 2022-05-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-20 03:25:52
- Profile updated
- 2026-07-07 13:17:13
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:cn country_code:ru
Context
Lynx is a remote access Trojan known for its use in cyber espionage campaigns targeting government and telecommunications sectors. It is capable of stealth operations, data exfiltration, and remote command execution.
Detection coverage
- 2 YARA rules
Detection rules
- SIGNATURE_BASE_MAL_RANSOM_INC_Aug24 (yara-rule)
- MALPEDIA_Win_Lynx_Auto (yara-rule)
Reports & references
- esentire.com — Threat Actors Deploy Sinobi Ransomware Via Compromised Sonicwall Ssl Vpn Credentials (report)
- ransomlook.io — Lynx (report)
- Palo Alto Unit 42 — Inc Ransomware Rebrand To Lynx (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lynx (report)
- nextron-systems.com — In Depth Analysis Of Lynx Ransomware (report)
- ish.com.br — Ransomware Lynx Saiba Como Mitigar Essa Ameaca (report)
- group-ib.com — Cat S Out Of The Bag Lynx Ransomware (report)