SUBJECT PROFILE
Lynx/INC ransomware was newly linked on July 1, 2026, to the massive 'FortiBleed' credential theft campaign, which exposed credentials from over 73,000 FortiGate devices. SOCRadar's investigation identified a FortiBleed infrastructure server whose browser sessions accessed negotiation panels for both Lynx and INC, providing direct evidence of an affiliate overlap between the two groups. Lynx, which emerged in mid-2024, is broadly assessed by researchers as a rebrand of the INC ransomware operation. The FortiBleed operation used a custom 'FortiGate Sniffer' tool deployed on compromised firewalls to intercept VPN credentials in-transit from network traffic.
Financially motivated double-extortion ransomware; credential harvesting from network edge devices for network intrusion at scale
OPERATIONAL HISTORY
FortiGate firewall compromise, custom packet-sniffing tool (FortiGate Sniffer), VPN credential interception from live network traffic, downloaded FortiGate configuration file exfiltration, credential cracking and stuffing, double extortion (encrypt + leak), negotiation panel administration
KNOWN INFRASTRUCTURE
Custom FortiGate Sniffer malware; Windows staging servers; credential cracking infrastructure; Lynx and INC dark web leak/negotiation panels; FortiGate edge device botnet (73,000+ devices); stolen credential repositories