Lynx Ransomware Group

Threat Actor

The Lynx Ransomware-as-a-Service (RaaS) group has been found operating a highly organized platform, complete with a structured affiliate program and robust encryption methods. The group actively recruits experienced penetration testing teams through underground forums.

The group provides its affiliates with an "All-in-One Archive" that contains binaries for Windows, Linux, and ESXi environments.Affiliates receive an 80% share of ransom proceeds, handle all negotiations and maintain control over the ransom wallet. Lynx also offers additional services, such as a call center to harass victims and advanced storage solutions for high-performing affiliates.

Malware Used by this Threat Actor

No malware identified for this threat actor.