# Lynx Ransomware Deploys via Compromised RDP

Published: 2025-12-17 · Severity: medium
Canonical: https://vorant.io/reports/e3486691-8c78-545b-a5d6-add158716f02/lynx-ransomware-deploys-via-compromised-rdp

> A threat actor used stolen RDP credentials to move laterally, exfiltrate data via temp.sh, and deploy Lynx ransomware across backup and file servers over nine days.

The DFIR Report details an intrusion beginning with a valid, likely pre-compromised RDP login to an internet-exposed host, with no evidence of brute forcing—suggesting credentials sourced from an infostealer, breach reuse, or an initial access broker. The actor pivoted within ten minutes to a domain controller using separate domain admin credentials, created multiple look-alike privileged accounts for persistence, installed AnyDesk (though never used), and mapped virtualization and file-share infrastructure using SoftPerfect NetScan and later NetExec. Notably, both source IPs used throughout the intrusion were tied to Railnet LLC, identified by Intrinsec as bulletproof-hosting front for Virtualine, a Russia-based provider advertised on Exploit and XSS forums.

Over nine days, the actor returned intermittently to conduct further discovery, collect and 7-Zip sensitive files from network shares, and exfiltrate archives to the temporary file-sharing service temp.sh. On the final day, they accessed backup servers via RDP, deleted Veeam backup jobs to inhibit recovery, and deployed the Lynx ransomware binary (w.exe) across multiple backup and file servers with consistent command-line arguments. Total time-to-ransomware was approximately 178 hours.

The intrusion exemplifies a hands-on-keyboard RDP-centric operation with minimal malware footprint, relying almost entirely on valid credentials, living-off-the-land tools, and dual-use utilities (NetScan, NetExec, AnyDesk, 7-Zip) rather than custom implants, complicating detection until the ransomware deployment stage.

## Mentioned in this report

- Threat actors: Lynx ransomware group
- Malware: AnyDesk, Lynx, NetExec, SoftPerfect NetScan

Source reporting: https://thedfirreport.com/2025/12/17/cats-got-your-files-lynx-ransomware

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e3486691-8c78-545b-a5d6-add158716f02/lynx-ransomware-deploys-via-compromised-rdp.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
