Lynx Ransomware Deployed via Compromised RDP After Backup Deletion

Lynx Ransomware Deployed via Compromised RDP After Backup Deletion

First seen 18 Nov 2025, 09:16 UTC ScworldCybersecuritynewsGbhackersCyberpress 98% similarity 36.9

Article Content

Browse articles
ThreatCluster

Threat actors are exploiting compromised Remote Desktop Protocol (RDP) logins to deploy Lynx ransomware. The attackers are deleting server backups to maximize the impact of the ransomware, affecting organizations that rely on these backups for recovery. This tactic highlights the increasing sophistication of ransomware attacks in the cybersecurity landscape.

ThreatCluster AI How this analysis works

Community

Browse all →