lynx

Ransomware
Sourceransomware.live

About the group

Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300,000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group lynx has 4 known ransomware victims. See the most affected sectors and countries and recent victims.

4known victims
4in Brazil
2sectors hit
Most attacked sectors
Professional Services3
Manufacturing1
Most affected countries
🇧🇷 Brasil4
Recent victims
cibracoProfessional Services · BR · 2025-08-05
accountant falavinha.localProfessional Services · BR · 2025-06-10
GRECA Asfaltos (grupogreca.com.br)Manufacturing · BR · 2025-06-04
BeCleverProfessional Services · BR · 2024-10-24

lynx uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →