RansomwareThe DFIR Report·8 months ago
Cat’s Got Your Files: Lynx Ransomware
An intrusion involving Lynx ransomware began in early March 2025 through a single successful RDP logon to an internet-exposed system, with no evidence of credential stuffing or brute force attempts preceding the successful access. This suggests the attacker may have obtained valid credentials through other means before gaining initial access to the target environment.