Activity timeline
Lynx appears in 2 tracked threats between and ; the busiest month was 2026-06 with 1 report.
ATT&CK techniques observed
- T1018 Remote System Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1039 Data from Network Shared Drive — Collectionobserved in 2 of 2 tracked threats
- T1040 Network Sniffing — Credential Accessobserved in 2 of 2 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 2 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 2 of 2 tracked threats
- T1087 Account Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1098 Account Manipulation — Persistenceobserved in 2 of 2 tracked threats
- T1110 Brute Force — Credential Accessobserved in 2 of 2 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 2 of 2 tracked threats
- T1136 Create Account — Persistenceobserved in 2 of 2 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
- T1552 Unsecured Credentials — Credential Accessobserved in 2 of 2 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 2 of 2 tracked threats
- T1583 Acquire Infrastructure — Resource Developmentobserved in 2 of 2 tracked threats