As cited
Copy frozen at (site build).
ransomware
Cat’s Got Your Files: Lynx Ransomware
A ransomware intrusion labeled Lynx began in March 2025 when an attacker gained Remote Desktop Protocol access to an internet-exposed system. The successful logon showed no signs of brute force or credential stuffing, suggesting the attacker may have possessed valid credentials beforehand.
Why it matters: Organizations running internet-exposed RDP services face direct risk from Lynx operators, who gained initial access without obvious credential compromise techniques, implying need for review of RDP exposure and access controls.
- Source published
- First seen by Cybersecurity Tracker