Lynx Ransomware Attack Began with Compromised RDP Credentials

· Original article ↗

Summary

Attackers used valid RDP credentials to enter a network, create privileged accounts, exfiltrate files, and deploy Lynx ransomware on backup and file servers over a nine-day intrusion.

Key points

  • The intrusion began with a successful RDP login using valid credentials; investigators found no evidence of brute force and assessed the credentials were likely obtained beforehand.
  • About ten minutes later, the attackers used a separate domain administrator account to access a domain controller and created look-alike accounts in privileged groups.
  • Attackers used SoftPerfect Network Scanner and NetExec to enumerate systems, shares, and network infrastructure, then moved laterally through RDP.
  • They collected files from multiple network shares, compressed them with 7-Zip, and uploaded the archives to temp.sh.
  • On the ninth day, attackers deleted Veeam backup jobs and deployed Lynx ransomware across multiple backup and file servers.
  • The intrusion took about 178 hours from initial access to ransomware deployment; the article provides indicators and detection rules.

Article Details

Victim Organization
Not disclosed
Incident Type
Ransomware intrusion with confirmed data exfiltration and backup-job deletion
Data Types Exposed
  • Sensitive files collected from multiple network shares; specific contents were not disclosed
Affected Records
Not disclosed
Affected Data Size
Not disclosed
Operational Impact
Lynx ransomware was executed across multiple backup and file servers, targeting the E drive with fast-mode encryption. Backup jobs and backup configuration entries were deleted through Veeam Backup & Replication. The source did not disclose downtime or the full extent of encryption. The intrusion began in early March 2025 and spanned nine calendar days, with just under 178 hours from initial access to ransomware deployment.
Ransom Or Extortion
The ransomware dropped a ransom note. No ransom amount, payment, negotiation, or separate extortion demand was disclosed.
Claim Status
confirmed

Indicators of compromise

TypeIndicatorContext
IPV4195[.]211[.]190[.]189Initial-access RDP source IP explicitly listed in the source's indicator section.
IPV477[.]90[.]153[.]30Follow-up RDP source IP explicitly listed in the source's indicator section.
MD53073af95dfc18361caebccd69d0021a2Source-listed hash of netscan.exe, the network scanner deployed and used by the attacker.
MD57532ff90145b8c59dc9440bf43dc87a5Source-listed hash of nxc.exe, the NetExec executable used for SMB enumeration.
MD5e2179046b86deca297ebf7398b95e438Source-listed hash of w.exe, the Lynx ransomware payload executed on backup and file servers.
SHA12b4b11d3ecffd82ed44db652cdd65733224f8e34Source-listed hash of nxc.exe, the NetExec executable used for SMB enumeration.
SHA13e01df0155a539fe6d802ee9e9226d8c77fd96c9Source-listed hash of w.exe, the Lynx ransomware payload executed on backup and file servers.
SHA1efe8b9ff7ff93780c9162959a4c1e5ecf6e840a4Source-listed hash of netscan.exe, the network scanner deployed and used by the attacker.
SHA25607b36c1660deb223749a8ac151676d8924bc13aa59e6712a3c14a2df5237264aSource-listed hash of w.exe, the Lynx ransomware payload executed on backup and file servers.
SHA256517288e12c05a92e483e6d80b9136c19bc58c46851720680bb6d1b7016034c37Source-listed hash of netscan.exe, the network scanner deployed and used by the attacker.
SHA2566285d32a9491a0084da85a384a11e15e203badf67b1deed54155f02b7338b108Source-listed hash of nxc.exe, the NetExec executable used for SMB enumeration.

MITRE ATT&CK

T1012 · Query RegistryRegistry queries were used to identify virtualization hostnames and infrastructure.T1016 · System Network Configuration DiscoveryThe attacker ran ipconfig and route print to inspect network configuration.T1018 · Remote System DiscoveryThe attacker discovered remote systems using network scanning, ping, nslookup, and nbtstat.T1021.001 · Remote Desktop ProtocolRDP was used extensively for lateral movement to domain controllers, hypervisors, backup servers, and file servers.T1046 · Network Service DiscoverySoftPerfect Network Scanner and NetExec were used to discover hosts and network services.T1059.001 · PowerShellPowerShell was used to execute commands during interactive post-compromise activity.T1059.003 · Windows Command ShellWindows Command Shell was used for discovery commands and ransomware execution.T1078 · Valid AccountsThe attacker used already-compromised credentials, including a separate domain administrator account.T1082 · System Information DiscoverySystem information was collected with systeminfo and other Windows management utilities.T1087.001 · Local AccountThe attacker reviewed local accounts and permissions through the Local Users and Groups snap-in.T1098.007 · Additional Local or Domain GroupsNewly created accounts were added to privileged domain groups, including Domain Admins.T1110.003 · Password SprayingThe case summary reports a password spray over SMB port 445 using NetExec after initial compromise.T1133 · External Remote ServicesInitial access used valid credentials to log into an internet-exposed RDP server.T1135 · Network Share DiscoveryThe attacker enumerated network shares, including testing write access with SoftPerfect Network Scanner.T1136.002 · Domain AccountThe attacker created three look-alike domain accounts for persistence.T1219 · Remote Access ToolsAnyDesk was installed on a domain controller for persistence, but no subsequent use was observed.T1486 · Data Encrypted for ImpactLynx ransomware was executed on multiple backup and file servers with encryption arguments.T1490 · Inhibit System RecoveryThe attacker deleted backup jobs and removed backups from the backup configuration database.T1543.003 · Windows ServiceAnyDesk was installed as a Windows service on the domain controller.T1560.001 · Archive via UtilityThe attacker used 7-Zip to archive files collected from network shares.T1567 · Exfiltration Over Web ServiceCollected archives were uploaded to a temporary file-sharing web service.

People

Malware

Vendors

Products

Tools

Countries

Related Articles