Cat’s Got Your Files: Lynx Ransomware
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A detailed DFIR case study of a Lynx ransomware intrusion spanning nine days in early 2025. The threat actor gained initial access via RDP using pre-compromised credentials (likely from an infostealer or initial access broker), moved laterally to a domain controller within minutes, and created multiple lookalike domain admin accounts for persistence. Over the following days, they conducted extensive network enumeration using SoftPerfect Network Scanner and NetExec, exfiltrated compressed file archives via temp.sh, deleted Veeam backup jobs, and finally deployed Lynx ransomware across backup and file servers. The total Time to Ransomware was approximately 178 hours. Infrastructure used was traced to Railnet LLC, a front for Russian bulletproof hosting provider Virtualine. Includes full MITRE ATT&CK mapping, IOCs, Sigma rules, and YARA signatures.