VORANT. Threat Intelligence Sign in Get the full feed

Lynx ransomware hits via RDP, 178-hour TTR

high threat

Threat actors deployed Lynx ransomware across backup and file servers after nine days of RDP-based lateral movement, credential abuse, exfiltration via temp.sh, and Veeam backup deletion.

In early March 2025, threat actors gained initial access to a victim network via RDP using pre-compromised credentials—likely sourced from infostealers, data breaches, or an initial access broker. Within ten minutes, the actor pivoted to a domain controller using separate domain admin credentials and created three impersonation-style accounts ("administratr" and two lookalikes), adding them to Domain Admins and other privileged groups. The actor installed AnyDesk for persistence but never used it, relying exclusively on RDP throughout the intrusion.

Over the following days, the actor mapped virtualization infrastructure with SoftPerfect Network Scanner, enumerated hosts with NetExec password spraying over SMB, and browsed multiple file shares. On day six, they collected sensitive files, compressed them with 7-Zip, and exfiltrated the archives to temp.sh. On day nine, the actor returned via RDP, connected to backup servers, deleted Veeam backup jobs via the console, and deployed Lynx ransomware (w.exe) with fast-mode encryption (5% of files) across multiple backup and file servers. Time to ransomware was approximately 178 hours over nine calendar days. Both source IPs (195.211.190.189 and 77.90.153.30) were hosted on Railnet LLC infrastructure, identified as a front for Russian bulletproof hosting provider Virtualine.

Mentioned in this report

Malware Lynx

Source reporting: https://thedfirreport.com/2025/12/17/cats-got-your-files-lynx-ransomware

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free