Skip to content
Lynx Ransomware Deployed via Compromised RDP After Backup Deletion

Lynx Ransomware Deployed via Compromised RDP After Backup Deletion

First seen 18 Nov 2025, 09:16 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Threat actors are exploiting compromised Remote Desktop Protocol (RDP) logins to deploy Lynx ransomware. The attackers are deleting server backups to maximize the impact of the ransomware, affecting organizations that rely on these backups for recovery. This tactic highlights the increasing sophistication of ransomware attacks in the cybersecurity landscape.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 203d ago How this analysis works

More articles in this cluster (5)

Following this threat?

Track Cephalus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed