Incident response · Lynx ransomware
Hit by Lynx ransomware? Most of each large file is probably still there.
Lynx has listed Australian organisations steadily since 2024: a manufacturer, a construction firm, a truck dealership, a barristers' chambers, an aged-care provider, a school. It is built on the INC Ransom code base and it inherits INC's habit of encrypting only a share of each file. In its default mode that share is 15 percent. The other 85 percent is still on disk, and that is where a recovery starts.
Recognise it
How to confirm it is Lynx.
Before anything else, keep the encrypted files and every ransom note exactly where they are. They identify the strain, and they are often the raw material a recovery works from.
- File extension
- .LYNX appended to encrypted files (some samples write it in lower case as .lynx)
- Ransom note
- README.txt in every encrypted folder, the desktop wallpaper replaced, and the note printed to every printer it can reach
- First seen
- July 2024, on a leak site called Lynx News. Widely assessed as a successor to INC Ransom, whose source code was offered for sale earlier that year
- Typical entry
- Remote Desktop and SSL VPN gateways with stolen or sprayed passwords and no multi-factor authentication, and remote management tools left without MFA
Behaviour
What Lynx does to your systems.
Encryption depth is a mode
The affiliate picks fast, medium, slow or entire, which encrypt 5, 15, 25 or 100 percent of each file. Medium is the default. Analysis of the encryptor shows it working in blocks, encrypting one and skipping the next several.
Shadow copies deleted
Lynx removes Windows volume shadow copies and uses the Restart Manager to unlock files that are open, so the easy restore path is gone and running applications do not protect their data.
Data taken first
Files are exfiltrated before encryption, in documented cases with 7-Zip and MEGA or Rclone, and the leak site is used as the second lever. Lynx does publish when victims do not pay.
Hybrid encryption, no public decryptor
AES in counter mode with Curve25519 key exchange. There is no known flaw and no free decryptor, so a recovery works with the data that was never encrypted.
Windows, Linux and ESXi
Lynx ships builds for Windows, several Linux architectures and VMware ESXi. Australian cases have seen the hypervisor targeted directly, so virtual estates are squarely in scope.
Active against Australia
At least nine Australian organisations have been listed since August 2024, across manufacturing, construction, wholesale, legal, aged care, education and mining. The group's stated policy of avoiding healthcare has not held.
The honest answer
Can Lynx-encrypted files be recovered?
Often, substantially, yes. Lynx's speed comes from encrypting a set share of each file and leaving the rest alone. On a large database, virtual disk or archive that leaves most of the underlying data physically intact, recoverable by locating the untouched structures and rebuilding them without any key. The default medium mode is the most common configuration we see, and it is a good candidate.
Two honest caveats. If the affiliate chose entire mode, the file is fully encrypted and only backups bring it back. And small files are usually a loss whatever the mode, because a small file fits inside the first encrypted block. The strain build and a sample of encrypted files tell us within hours which situation you are in.
Keep every encrypted file and every README.txt where it is, and do not let anyone rebuild affected machines or ESXi hosts before the assessment. The note's victim ID and the file sizes are the raw material a recovery works from.
Common questions
Lynx, in plain terms.
Mid-incident and need a straight answer? Call 1300 004 766. A person answers, 24 hours a day.
What is the .LYNX file extension?
Files renamed with a .LYNX (or .lynx) extension have been encrypted by the Lynx ransomware operation, active since July 2024 and built on the INC Ransom code base. The ransom note is README.txt, dropped in every affected folder and often printed on office printers. Keep the files and notes; they identify the build and are frequently the basis of a recovery.
Can .LYNX files be decrypted for free?
No. Lynx uses AES with a Curve25519 key exchange and no flaw has been found in it, so there is no public decryptor and nothing on nomoreransom.org. The realistic recovery paths are backups, snapshots, and recovery of the data Lynx never encrypted, which in its default mode is most of every large file.
Can Lynx-encrypted files be recovered without paying?
Often, partially, and sometimes substantially. Lynx encrypts 5, 15 or 25 percent of each file unless the affiliate chose entire mode, so databases, virtual disks and archives usually retain most of their data intact. That intact data can be located, carved and rebuilt without the attacker's key. It is a recovery effort with honest limits rather than a guarantee, and small fully encrypted files are usually a loss without backups.
Is Lynx the same as INC Ransom?
It is closely related. INC Ransom's source code was offered for sale on criminal forums in early 2024 and Lynx appeared that July with a large share of the same functions, so most researchers describe it as a rebrand or successor. In practice that matters because Lynx inherits INC's partial encryption, which is what makes recovery possible.
Lynx hit our ESXi hosts. Does that change anything?
The mechanics change and the principle holds. The Lynx ESXi build encrypts virtual machine disk files on the datastore, and VMDKs are exactly the kind of large structured file where partial encryption leaves a great deal intact. Do not delete or recreate the datastores, and do not reinstall the host. Leave everything in place and get an assessment first.
What should we do in the first hour?
Isolate the affected machines but leave them powered on, keep every encrypted file and README.txt, take surviving backups offline, and start a simple timeline of what happened when. Lynx affiliates set short leak deadlines, often two to four days, so the data question needs a decision in parallel with recovery. Do not rebuild, do not run cleanup tools, and do not pay in a panic. Our First-Response Guide covers this on one printable page, and 1300 004 766 is answered around the clock.
Not Lynx?
The extension on your files names the strain.
If the note or extension does not match what is on this page, one of these may fit. If none of them do, call anyway: the strain shapes the recovery, but identifying it is our job, not yours.
.akira
Akira →
Consistently among the most active strains in Australia. Partial encryption by design.
random extension
Qilin →
The most active operation of 2026. Every victim gets a unique file extension.
.inc
INC Ransom →
Subject of a 2026 ACSC joint advisory. Heavy targeting of Australian healthcare.
.fog / .flocked
Fog →
Education-focused, enters via VPN credentials, attacks backups first.
.safepay
SafePay →
Encryption depth is a setting, and operators pick shallow. Enters on valid VPN and RDP credentials.
.dragonforce_encrypted
DragonForce →
Full, partial or header-only per file. Dedicated ESXi builds hit whole virtual estates.
no extension (via your IT provider)
Storm →
New in August 2026. Reaches Australian businesses through a compromised IT provider and lists them with long countdowns.
no extension (theft only)
Kairos →
Never encrypts. Steals data and runs a seven-day clock. Nine Australian victims since 2024.
Or start from ransomware recovery, which covers the method whatever the strain turns out to be.
Right now
The first hours decide what can be saved.
Isolate the machines, keep the encrypted files, take backups offline, and call before anything gets rebuilt. Australian incident response, answered by a real person.