DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // LYNX-INC-FORTIBLEEDFIRST SEEN: AUG 2023

LYNX / INC RANSOMWARE

ALSO KNOWN AS: INC Ransom, Lynx RaaS
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (Eastern Europe suspected)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:AUG 2023
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL69/100
RESOURCES69/100
PERSISTENCE72/100
STEALTH64/100
IMPACT78/100

Lynx/INC ransomware was newly linked on July 1, 2026, to the massive 'FortiBleed' credential theft campaign, which exposed credentials from over 73,000 FortiGate devices. SOCRadar's investigation identified a FortiBleed infrastructure server whose browser sessions accessed negotiation panels for both Lynx and INC, providing direct evidence of an affiliate overlap between the two groups. Lynx, which emerged in mid-2024, is broadly assessed by researchers as a rebrand of the INC ransomware operation. The FortiBleed operation used a custom 'FortiGate Sniffer' tool deployed on compromised firewalls to intercept VPN credentials in-transit from network traffic.

Financially motivated double-extortion ransomware; credential harvesting from network edge devices for network intrusion at scale

FortiGate firewall compromise, custom packet-sniffing tool (FortiGate Sniffer), VPN credential interception from live network traffic, downloaded FortiGate configuration file exfiltration, credential cracking and stuffing, double extortion (encrypt + leak), negotiation panel administration

ENTERPRISE NETWORKS
HEALTHCARE
MANUFACTURING
CRITICAL INFRASTRUCTURE
GOVERNMENT

Custom FortiGate Sniffer malware; Windows staging servers; credential cracking infrastructure; Lynx and INC dark web leak/negotiation panels; FortiGate edge device botnet (73,000+ devices); stolen credential repositories

FILE DATE: JUL 2026
FortiBleed Attribution to Lynx/INC
SOCRadar linked the FortiBleed operation — which harvested credentials from 73,000+ Fortinet devices using a custom FortiGate Sniffer — directly to INC and Lynx ransomware affiliate infrastructure on July 1, 2026, via shared negotiation panel access.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn