# Lynx ransomware hits via RDP, 178-hour TTR

Published: 2025-12-17 · Severity: high
Canonical: https://vorant.io/reports/e3486691-8c78-545b-a5d6-add158716f02/lynx-ransomware-hits-via-rdp-178-hour-ttr

> Threat actors deployed Lynx ransomware across backup and file servers after nine days of RDP-based lateral movement, credential abuse, exfiltration via temp.sh, and Veeam backup deletion.

In early March 2025, threat actors gained initial access to a victim network via RDP using pre-compromised credentials—likely sourced from infostealers, data breaches, or an initial access broker. Within ten minutes, the actor pivoted to a domain controller using separate domain admin credentials and created three impersonation-style accounts ("administratr" and two lookalikes), adding them to Domain Admins and other privileged groups. The actor installed AnyDesk for persistence but never used it, relying exclusively on RDP throughout the intrusion.

Over the following days, the actor mapped virtualization infrastructure with SoftPerfect Network Scanner, enumerated hosts with NetExec password spraying over SMB, and browsed multiple file shares. On day six, they collected sensitive files, compressed them with 7-Zip, and exfiltrated the archives to temp.sh. On day nine, the actor returned via RDP, connected to backup servers, deleted Veeam backup jobs via the console, and deployed Lynx ransomware (w.exe) with fast-mode encryption (5% of files) across multiple backup and file servers. Time to ransomware was approximately 178 hours over nine calendar days. Both source IPs (195.211.190.189 and 77.90.153.30) were hosted on Railnet LLC infrastructure, identified as a front for Russian bulletproof hosting provider Virtualine.

## Mentioned in this report

- Malware: Lynx

Source reporting: https://thedfirreport.com/2025/12/17/cats-got-your-files-lynx-ransomware

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e3486691-8c78-545b-a5d6-add158716f02/lynx-ransomware-hits-via-rdp-178-hour-ttr.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
