216.73.216.226

Ransomware Roundup – Lynx

· Published 17/02/2025 10:54 · Modified 17/02/2025 11:22

Export JSON

Essential information

Published
17/02/2025 10:54
Modified
17/02/2025 11:22
Tags
2025-02-17 brave prince construction data leak encryption lynx manufacturing ransomware windows
Related entities
9 observables, 1 intrusion sets (apt), 15 techniques (mitre), 2 malware, 7 others

Description

The , first detected in July 2024, is a -targeting malware that encrypts files and demands ransom for decryption. It shares similarities with the INC but offers more granular control. encrypts files with a . extension, changes desktop backgrounds, and prints ransom notes. It targets specific processes and services, avoiding certain folders and file types. The has affected 96 victims across 16 countries, primarily in the United States, with and industries most impacted. Despite claims of excluding certain sectors, some healthcare and energy organizations have been targeted. Fortinet products offer protection against through various security measures.

External references