DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // LYNX-INC-FORTIBLEEDFIRST SEEN: AUG 2023

LYNX / INC RANSOMWARE

ALSO KNOWN AS: INC Ransom, Lynx RaaS
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (Eastern Europe suspected)
ATTRIBUTION:ORGANIZED CRIME
STATUS:● ACTIVE
FIRST OBSERVED:AUG 2023
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL69/100
RESOURCES69/100
PERSISTENCE72/100
STEALTH64/100
IMPACT78/100

Lynx/INC ransomware was newly linked on July 1, 2026, to the massive 'FortiBleed' credential theft campaign, which exposed credentials from over 73,000 FortiGate devices. SOCRadar's investigation identified a FortiBleed infrastructure server whose browser sessions accessed negotiation panels for both Lynx and INC, providing direct evidence of an affiliate overlap between the two groups. Lynx, which emerged in mid-2024, is broadly assessed by researchers as a rebrand of the INC ransomware operation. The FortiBleed operation used a custom 'FortiGate Sniffer' tool deployed on compromised firewalls to intercept VPN credentials in-transit from network traffic.

Financially motivated double-extortion ransomware; credential harvesting from network edge devices for network intrusion at scale

FortiGate firewall compromise, custom packet-sniffing tool (FortiGate Sniffer), VPN credential interception from live network traffic, downloaded FortiGate configuration file exfiltration, credential cracking and stuffing, double extortion (encrypt + leak), negotiation panel administration

ENTERPRISE NETWORKS
HEALTHCARE
MANUFACTURING
CRITICAL INFRASTRUCTURE
GOVERNMENT

Custom FortiGate Sniffer malware; Windows staging servers; credential cracking infrastructure; Lynx and INC dark web leak/negotiation panels; FortiGate edge device botnet (73,000+ devices); stolen credential repositories

FILE DATE: JUL 2026
FortiBleed Attribution to Lynx/INC
SOCRadar linked the FortiBleed operation — which harvested credentials from 73,000+ Fortinet devices using a custom FortiGate Sniffer — directly to INC and Lynx ransomware affiliate infrastructure on July 1, 2026, via shared negotiation panel access.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn