SYMBOLCOMMON_NAMEaka. SYNONYMS
win.lynx (Back to overview)

Lynx

VTCollection    

According to Nextron, Lynx ransomware is a sophisticated malware threat that has been active since mid-2024. Lynx has claimed over 20 victims across a range of industries. Once it infiltrates a system, it encrypts critical files, appending a ‘.lynx’ extension, and deletes backup files like shadow copies to hinder recovery. Uniquely, it also sends the ransom note to available printers, adding an unexpected element to its attack strategy. This malware shares similarities with previous INC ransomware, indicating that they bought INC ransomware source code.

References
2025-08-27 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
Threat Actors Deploy Sinobi Ransomware via Compromised SonicWall SSL VPN Credentials
Lynx Sinobi
2025-03-26 ⋅ ⋅ ISH Tecnologia ⋅ 0x0d4y, Ismael Rocha
ffdgf
Lynx
2025-01-28 ⋅ Group-IB ⋅ Nikolay Kichatov, Pietro Albuquerque, Sharmine Low
Cat’s out of the bag: Lynx Ransomware-as-a-Service
Lynx
2024-10-11 ⋅ Nextron Systems ⋅ Nextron Threat Research Team
In-Depth Analysis of Lynx Ransomware
Lynx
2024-10-10 ⋅ paloalto Netoworks: Unit42 ⋅ Benjamin Chang, Micah Yates, Pranay Kumar Chhaparwal
Lynx Ransomware: A Rebranding of INC Ransomware
INC Lynx
Yara Rules
[TLP:WHITE] win_lynx_auto (20260917 | Detects win.lynx.)
rule win_lynx_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.lynx."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lynx"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { ff75ec ff15???????? 6a00 6a00 57 53 }
            // n = 6, score = 100
            //   ff75ec               | push                dword ptr [ebp - 0x14]
            //   ff15????????         |                     
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   57                   | push                edi
            //   53                   | push                ebx

        $sequence_1 = { 8d8dfcfcffff e8???????? 8d8dfcfcffff e8???????? 8b8524fbffff 8d8d5cffffff 0f1085c4feffff }
            // n = 7, score = 100
            //   8d8dfcfcffff         | lea                 ecx, [ebp - 0x304]
            //   e8????????           |                     
            //   8d8dfcfcffff         | lea                 ecx, [ebp - 0x304]
            //   e8????????           |                     
            //   8b8524fbffff         | mov                 eax, dword ptr [ebp - 0x4dc]
            //   8d8d5cffffff         | lea                 ecx, [ebp - 0xa4]
            //   0f1085c4feffff       | movups              xmm0, xmmword ptr [ebp - 0x13c]

        $sequence_2 = { 50 6a00 6800120000 ff15???????? 8d8424b8000000 50 56 }
            // n = 7, score = 100
            //   50                   | push                eax
            //   6a00                 | push                0
            //   6800120000           | push                0x1200
            //   ff15????????         |                     
            //   8d8424b8000000       | lea                 eax, [esp + 0xb8]
            //   50                   | push                eax
            //   56                   | push                esi

        $sequence_3 = { c744244001001000 0f10442434 c744244400000000 c744244c00000000 03c0 c744245000000000 0f11842490000000 }
            // n = 7, score = 100
            //   c744244001001000     | mov                 dword ptr [esp + 0x40], 0x100001
            //   0f10442434           | movups              xmm0, xmmword ptr [esp + 0x34]
            //   c744244400000000     | mov                 dword ptr [esp + 0x44], 0
            //   c744244c00000000     | mov                 dword ptr [esp + 0x4c], 0
            //   03c0                 | add                 eax, eax
            //   c744245000000000     | mov                 dword ptr [esp + 0x50], 0
            //   0f11842490000000     | movups              xmmword ptr [esp + 0x90], xmm0

        $sequence_4 = { 8bc7 83e03f 6bc838 8b0495708f4200 f644082801 740d 56 }
            // n = 7, score = 100
            //   8bc7                 | mov                 eax, edi
            //   83e03f               | and                 eax, 0x3f
            //   6bc838               | imul                ecx, eax, 0x38
            //   8b0495708f4200       | mov                 eax, dword ptr [edx*4 + 0x428f70]
            //   f644082801           | test                byte ptr [eax + ecx + 0x28], 1
            //   740d                 | je                  0xf
            //   56                   | push                esi

        $sequence_5 = { 6a00 53 c745dc01000000 894de4 c745e802000000 ff15???????? 85c0 }
            // n = 7, score = 100
            //   6a00                 | push                0
            //   53                   | push                ebx
            //   c745dc01000000       | mov                 dword ptr [ebp - 0x24], 1
            //   894de4               | mov                 dword ptr [ebp - 0x1c], ecx
            //   c745e802000000       | mov                 dword ptr [ebp - 0x18], 2
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax

        $sequence_6 = { 8bcf 8bc7 899d0cfdffff c1e012 0bd0 c1e909 }
            // n = 6, score = 100
            //   8bcf                 | mov                 ecx, edi
            //   8bc7                 | mov                 eax, edi
            //   899d0cfdffff         | mov                 dword ptr [ebp - 0x2f4], ebx
            //   c1e012               | shl                 eax, 0x12
            //   0bd0                 | or                  edx, eax
            //   c1e909               | shr                 ecx, 9

        $sequence_7 = { 33c7 8bbd54fcffff 23bd5cfdffff 33c7 8bbd34fdffff 018570fdffff 8d0419 }
            // n = 7, score = 100
            //   33c7                 | xor                 eax, edi
            //   8bbd54fcffff         | mov                 edi, dword ptr [ebp - 0x3ac]
            //   23bd5cfdffff         | and                 edi, dword ptr [ebp - 0x2a4]
            //   33c7                 | xor                 eax, edi
            //   8bbd34fdffff         | mov                 edi, dword ptr [ebp - 0x2cc]
            //   018570fdffff         | add                 dword ptr [ebp - 0x290], eax
            //   8d0419               | lea                 eax, [ecx + ebx]

        $sequence_8 = { 8d442468 50 ff742414 68???????? e8???????? 83c40c }
            // n = 6, score = 100
            //   8d442468             | lea                 eax, [esp + 0x68]
            //   50                   | push                eax
            //   ff742414             | push                dword ptr [esp + 0x14]
            //   68????????           |                     
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc

        $sequence_9 = { d1e9 8d34fd00000000 c1e21f 0bd1 89bd50fdffff 8b08 33da }
            // n = 7, score = 100
            //   d1e9                 | shr                 ecx, 1
            //   8d34fd00000000       | lea                 esi, [edi*8]
            //   c1e21f               | shl                 edx, 0x1f
            //   0bd1                 | or                  edx, ecx
            //   89bd50fdffff         | mov                 dword ptr [ebp - 0x2b0], edi
            //   8b08                 | mov                 ecx, dword ptr [eax]
            //   33da                 | xor                 ebx, edx

    condition:
        7 of them and filesize < 363520
}
Download all Yara Rules