Threat Actor

Lynx

Properties

summary
Lynx ransomware operation was linked to the FortiBleed credential theft campaign, using stolen Fortinet credentials for follow-on intrusions.
first_seen
2026-07-06T04:00:29.739771+00:00
last_seen
2026-07-06T04:00:29.739771+00:00
created_at
2026-07-06T04:00:29.739771+00:00
mention_count
1
evidence_url
https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html
target
multiple sectors
provenance
news-scan
suspected_origin
unknown
scan_confidence
0.85
status
pending

Explore this actor's full graph with Ninja Signal

Lynx — Threat Actor Profile — Ninja Signal | Ninja Signal