Lynx Ransomware Attack Began with Compromised RDP Credentials

Summary
Attackers used valid RDP credentials to enter a network, create privileged accounts, exfiltrate files, and deploy Lynx ransomware on backup and file servers over a nine-day intrusion.
Key points
- The intrusion began with a successful RDP login using valid credentials; investigators found no evidence of brute force and assessed the credentials were likely obtained beforehand.
- About ten minutes later, the attackers used a separate domain administrator account to access a domain controller and created look-alike accounts in privileged groups.
- Attackers used SoftPerfect Network Scanner and NetExec to enumerate systems, shares, and network infrastructure, then moved laterally through RDP.
- They collected files from multiple network shares, compressed them with 7-Zip, and uploaded the archives to temp.sh.
- On the ninth day, attackers deleted Veeam backup jobs and deployed Lynx ransomware across multiple backup and file servers.
- The intrusion took about 178 hours from initial access to ransomware deployment; the article provides indicators and detection rules.
Article Details
- Victim Organization
- Not disclosed
- Incident Type
- Ransomware intrusion with confirmed data exfiltration and backup-job deletion
- Data Types Exposed
- Sensitive files collected from multiple network shares; specific contents were not disclosed
- Affected Records
- Not disclosed
- Affected Data Size
- Not disclosed
- Operational Impact
- Lynx ransomware was executed across multiple backup and file servers, targeting the E drive with fast-mode encryption. Backup jobs and backup configuration entries were deleted through Veeam Backup & Replication. The source did not disclose downtime or the full extent of encryption. The intrusion began in early March 2025 and spanned nine calendar days, with just under 178 hours from initial access to ransomware deployment.
- Ransom Or Extortion
- The ransomware dropped a ransom note. No ransom amount, payment, negotiation, or separate extortion demand was disclosed.
- Claim Status
- confirmed
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 195[.]211[.]190[.]189 | Initial-access RDP source IP explicitly listed in the source's indicator section. |
| IPV4 | 77[.]90[.]153[.]30 | Follow-up RDP source IP explicitly listed in the source's indicator section. |
| MD5 | 3073af95dfc18361caebccd69d0021a2 | Source-listed hash of netscan.exe, the network scanner deployed and used by the attacker. |
| MD5 | 7532ff90145b8c59dc9440bf43dc87a5 | Source-listed hash of nxc.exe, the NetExec executable used for SMB enumeration. |
| MD5 | e2179046b86deca297ebf7398b95e438 | Source-listed hash of w.exe, the Lynx ransomware payload executed on backup and file servers. |
| SHA1 | 2b4b11d3ecffd82ed44db652cdd65733224f8e34 | Source-listed hash of nxc.exe, the NetExec executable used for SMB enumeration. |
| SHA1 | 3e01df0155a539fe6d802ee9e9226d8c77fd96c9 | Source-listed hash of w.exe, the Lynx ransomware payload executed on backup and file servers. |
| SHA1 | efe8b9ff7ff93780c9162959a4c1e5ecf6e840a4 | Source-listed hash of netscan.exe, the network scanner deployed and used by the attacker. |
| SHA256 | 07b36c1660deb223749a8ac151676d8924bc13aa59e6712a3c14a2df5237264a | Source-listed hash of w.exe, the Lynx ransomware payload executed on backup and file servers. |
| SHA256 | 517288e12c05a92e483e6d80b9136c19bc58c46851720680bb6d1b7016034c37 | Source-listed hash of netscan.exe, the network scanner deployed and used by the attacker. |
| SHA256 | 6285d32a9491a0084da85a384a11e15e203badf67b1deed54155f02b7338b108 | Source-listed hash of nxc.exe, the NetExec executable used for SMB enumeration. |
MITRE ATT&CK
T1012 · Query RegistryRegistry queries were used to identify virtualization hostnames and infrastructure.T1016 · System Network Configuration DiscoveryThe attacker ran ipconfig and route print to inspect network configuration.T1018 · Remote System DiscoveryThe attacker discovered remote systems using network scanning, ping, nslookup, and nbtstat.T1021.001 · Remote Desktop ProtocolRDP was used extensively for lateral movement to domain controllers, hypervisors, backup servers, and file servers.T1046 · Network Service DiscoverySoftPerfect Network Scanner and NetExec were used to discover hosts and network services.T1059.001 · PowerShellPowerShell was used to execute commands during interactive post-compromise activity.T1059.003 · Windows Command ShellWindows Command Shell was used for discovery commands and ransomware execution.T1078 · Valid AccountsThe attacker used already-compromised credentials, including a separate domain administrator account.T1082 · System Information DiscoverySystem information was collected with systeminfo and other Windows management utilities.T1087.001 · Local AccountThe attacker reviewed local accounts and permissions through the Local Users and Groups snap-in.T1098.007 · Additional Local or Domain GroupsNewly created accounts were added to privileged domain groups, including Domain Admins.T1110.003 · Password SprayingThe case summary reports a password spray over SMB port 445 using NetExec after initial compromise.T1133 · External Remote ServicesInitial access used valid credentials to log into an internet-exposed RDP server.T1135 · Network Share DiscoveryThe attacker enumerated network shares, including testing write access with SoftPerfect Network Scanner.T1136.002 · Domain AccountThe attacker created three look-alike domain accounts for persistence.T1219 · Remote Access ToolsAnyDesk was installed on a domain controller for persistence, but no subsequent use was observed.T1486 · Data Encrypted for ImpactLynx ransomware was executed on multiple backup and file servers with encryption arguments.T1490 · Inhibit System RecoveryThe attacker deleted backup jobs and removed backups from the backup configuration database.T1543.003 · Windows ServiceAnyDesk was installed as a Windows service on the domain controller.T1560.001 · Archive via UtilityThe attacker used 7-Zip to archive files collected from network shares.T1567 · Exfiltration Over Web ServiceCollected archives were uploaded to a temporary file-sharing web service.
People
Malware
Vendors
Railnet LLCNotably, both IP addresses involved were associated with Railnet LLC, a company previously identified as a front for Virtualine, which is known to operate infrastructure tied to IP ranges reportedly leveraged byVeeamIn particular, the RDP bitmap cache of the beachhead host shows the threat actor opening the Veeam Backup & Replication console.VirtualineIP addresses involved were associated with Railnet LLC, a company previously identified as a front for Virtualine, which is known to operate infrastructure tied to IP ranges reportedly leveraged by criminal networks.
Products
7-ZipSensitive files from multiple network shares were collected, compressed using 7-Zip, and exfiltrated via temporary file-sharing service temp.sh .AnyDeskTo establish persistence, the threat actor installed the AnyDesk remote access client on the domain controller.Hyper-VNext, the threat actor pivoted to mapping out the Hyper-V infrastructure, as we observed RDP connections from the beachhead host to three hypervisors.Veeam Backup & ReplicationIn particular, the RDP bitmap cache of the beachhead host shows the threat actor opening the Veeam Backup & Replication console.