Lynx Ransomware Group
Threat Actor
The Lynx Ransomware-as-a-Service (RaaS) group has been found operating a highly organized platform, complete with a structured affiliate program and robust encryption methods. The group actively recruits experienced penetration testing teams through underground forums.
The group provides its affiliates with an "All-in-One Archive" that contains binaries for Windows, Linux, and ESXi environments.Affiliates receive an 80% share of ransom proceeds, handle all negotiations and maintain control over the ransom wallet. Lynx also offers additional services, such as a call center to harass victims and advanced storage solutions for high-performing affiliates.
Incidents Associated with this Threat
- February 25, 2025: 800 GB Databreach at German Manufacturer Stürmer Maschinen
- January 22, 2025: Australian Automotive Manufacturer Confirms Cyberattack
Malware Used by this Threat Actor
No malware identified for this threat actor.
