Beyond the Leak Site: Uncovering Lynx Ransomware's Infrastructure

Ransomware operations have evolved well beyond encrypting files and demanding payment. Many now function as structured criminal enterprises, maintaining dedicated leak sites, communication portals, and supporting infrastructure designed to pressure victims, manage negotiations, and reinforce their public presence. While these websites often become the most visible part of a ransomware operation, they rarely tell the full story.

Lynx is one such group. Since emerging on the ransomware landscape, it has established an online presence that extends beyond publishing victim information. Like many modern ransomware operations, its infrastructure consists of multiple interconnected components that each serve a distinct purpose, offering valuable insight into how the group presents itself and supports its activities.

This report explores Lynx's publicly accessible infrastructure through a technical investigation conducted using StealthMole. By following infrastructure pivots, examining hidden services, and correlating findings across multiple StealthMole datasets, the investigation moves beyond the group's leak site to build a broader picture of its operational footprint. Rather than focusing on individual attacks or victim disclosures, the report examines the digital infrastructure surrounding the operation and the intelligence that can be uncovered by following those connections.

Behind the Curtain

The investigation began in StealthMole's Government Monitoring module, where a search for "Lynx" returned 8 government-sector organizations that had been listed by the group. The most recent entry was the Talbot County Department of Emergency Services (DES), whose disclosure page included a description of the organization, its reported annual revenue, and the date the listing was published. While the victim itself was not the focus of this investigation, the listing provided an entry point into Lynx's ecosystem and established a starting point for exploring the infrastructure supporting its operations.

  • http://lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion/leaks

To understand the broader scope of the group, the investigation then shifted to StealthMole's Ransomware Monitoring module. A further search of Lynx revealed a significantly larger operational footprint, with 397 victims indexed between July 2024 and August 2026. The volume of disclosures demonstrated that the Talbot County incident was not an isolated event but part of an active ransomware campaign that had persisted for more than two years. More importantly, the historical records offered an opportunity to look beyond recent activity and trace how the group's infrastructure had evolved over time.

Rather than concentrating on the latest disclosures alone, earlier victim listings were examined to identify infrastructure that might no longer be visible through the current leak site. One of the earliest indexed entries, published in August 2024, pointed to a different leak page hosted at:

  • http://lynxblog.******/leaks/66a***********331

This historical listing proved particularly valuable. In addition to the victim information, it exposed several operational artifacts that were absent from more recent disclosures, including the ProtonMail address james*******0@proton.me and a dedicated Tor-based negotiation portal:

  • http://lynxch*********************************qiyqd.onion/login

Victims were also instructed to register using an unique identifier before initiating negotiations. These details suggested that the historical leak page offered far more than a record of a past victim. It provided the first tangible links to the group's operational infrastructure and presented several new avenues for investigation.

  • 66*****************cb4e

Inside the Infrastructure

With historical artifacts pointing towards multiple operational components, the investigation turned to Lynx's current infrastructure to determine how the group maintained its public presence and whether traces of its wider ecosystem remained accessible.

  • lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion

A review of the site confirmed that it remained active at the time of the investigation. Its homepage followed the structure commonly adopted by modern ransomware operations, providing access to sections dedicated to News, Leaks, and Report, while continuing to publish victim disclosures through an actively maintained leak portal. StealthMole's historical records showed that the hidden service was first observed on 20 August 2024 and remained active as of 11 August 2026, demonstrating that the infrastructure had been operational for nearly two years.

The leak portal itself contained the latest victim disclosures. Alongside each victim listing, the site published organizational descriptions, reported revenue, publication dates, and supporting proof files, reflecting the group's continued use of public disclosures as a means of pressuring victims during negotiations.

Rather than stopping at the homepage, the investigation expanded to examine the hidden service itself. Several publicly accessible pages were identified, each providing a clearer picture of how the platform was structured.

Component

URL

Login Portal

http://lynxchat***********knad.onion/main/chat

Registration Portal

http://lynxchat************knad.onion/register

Chat Interface

http://lynxchat***********knad.onion/main/chat

Server Status

http://lynxchat*******knad.onion/server-status

The login interface required registered credentials, while the registration page prompted users to enter a unique identifier and password before creating an account. Combined with the dedicated chat interface, these pages indicate that the platform was designed to support authenticated victim communications rather than relying solely on email exchanges. An attempt to access the /server-status endpoint returned a 404 Page Not Found response, suggesting that the endpoint was either unavailable or intentionally inaccessible during the investigation.

The infrastructure also exposed additional technical metadata through StealthMole. The hidden service was identified as running nginx/1.27.5 While these metadata points do not independently reveal the group's operations, they provide additional artifacts that can be correlated with other datasets during an infrastructure investigation.

Connecting the Dots

With the current leak site confirmed to be active, the investigation shifted from examining the visible infrastructure to exploring the technical artifacts associated with it. Rather than relying solely on what could be observed through the website itself, StealthMole was used to pivot from the hidden service into related malware intelligence, allowing the investigation to uncover connections that would not have been apparent from the leak site alone.

  • lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion


Searching the current leak site, within StealthMole's Dark Web Tracker revealed 37 malware hashes associated with the domain. Rather than treating these as isolated indicators, each hash was investigated individually to determine whether it could provide additional insight into the group's operational infrastructure.

  • 0212*******************************************************7a5eb
  • 71db*******************************************************a0834
  • c587*******************************************************6d633
  • f85e*******************************************************0e619
  • 820e*******************************************************36f8a
  • 582e*******************************************************2fffe
  • 31de*******************************************************d5193
  • 5da4*******************************************************83040
  • bb4e*******************************************************f600a
  • f71f*******************************************************62787
  • 8090*******************************************************0c441
  • 97c8*******************************************************2ba00
  • 8569*******************************************************f5683
  • 432f*******************************************************29c66
  • d20c*******************************************************999f9
  • 468e*******************************************************89d6a
  • 0315*******************************************************21663
  • 589f*******************************************************21a23
  • 571f*******************************************************6cf8b
  • 551e*******************************************************ec386
  • 9a47*******************************************************a3896
  • ecbf*******************************************************f6e49
  • f9bb*******************************************************d56b7
  • 4e5b*******************************************************66412
  • c3b5*******************************************************24a18
  • 4ad4*******************************************************06ac4
  • 90ac*******************************************************cf7b8
  • ac68*******************************************************5b43f
  • dac3*******************************************************c94ed
  • cf7c*******************************************************7ac9c
  • 6486*******************************************************0313a
  • 0fb2*******************************************************1da93
  • ac50*******************************************************e9b60
  • dcba*******************************************************359cc
  • 4fbb*******************************************************4763b
  • 5533*******************************************************a931d
  • 1a01*******************************************************6ced0

One hash, in particular, proved especially valuable:

  • 4fb****************************************************763b

Using this artifact as a pivot uncovered a much broader network of Lynx-associated hidden services. The hash was linked to 14 separate Tor domains, consisting of both leak portals and negotiation portals.

Associated Leak Sites

Domain

Status

lynxblogco7r37jt7p5wrmfxzqze7ghxw6rihzkqc455qluacwotciyd.onion

Inactive

lynxblog************************************2sjyd.onion

Active

lynxblog***********************************2csyad.onion

Active

lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion

Inactive

lynxblog************************************omjad.onion

Active

lynxblog***********************************z3xwqd.onion

Active

lynxblog**********************************ngrfoid.onion

Active

Associated Negotiation Portals

Domain

Status

lynxchat**********************************dbsgmyd.onion

Active

lynxchatde4spv5x6xlwxf47jdo7wtwwgikdoeroxamphu3e7xx5doqd.onion

Inactive

lynxchatdy3tgcuijsqofhssopcepirjfq2f4pvb5qd4un4dhqyxswqd.onion

Inactive

lynxchat***********************************6quxqd.onion

Active

lynxchatfw4rgsclp4567i4llkqjr2kltaumwwobxdik3qa2oorrknad.onion

Inactive

lynxchatly4zludmhmi75jrwhycnoqvkxb4prohxmyzf4euf5gjxroad.onion

Inactive

lynxchatohmppv6au67lloc2vs6chy7nya7dsu2hhs55mcjxp2joglad.onion

Inactive

This single pivot expanded the investigation well beyond the original leak site, revealing multiple generations of Lynx infrastructure that included both active and inactive hidden services. Instead of a standalone website, the findings pointed towards an ecosystem of interconnected domains supporting different aspects of the group's operation.

The investigation continued by exploring additional Lynx-related domains identified through StealthMole, uncovering a further 16 hidden services sharing the group's naming convention. While their specific functions could not be determined from the available evidence, they collectively demonstrated that Lynx maintained a significantly broader Tor footprint than was immediately visible through its public leak site.

Among the additional infrastructure identified were:

  • lynx2*************************************fqiqd.onion
  • lynxa*************************************5daqd.onion
  • lynxo**************************************2oqd.onion
  • lynx2*************************************626yd.onion
  • lynxb************************************z3vvyd.onion
  • lynxk*************************************xc3ad.onion
  • lynxa*************************************whead.onion
  • lynxh*************************************feuid.onion
  • lynxc************************************v2pxyd.onion

while several additional domains were observed in an inactive state, suggesting that portions of the infrastructure had either been retired or replaced over time.

The infrastructure mapping did not end there. A further pivot into the hidden service

  • lynxbllrfr5262yvbgtqoyq76s7mpztcqkv6tjjxgpilpma7nyoeohyd.onion

identified three additional malware samples associated with the domain:

  • 9e565d*****************************************************345da
  • 730f82*****************************************************a753c
  • 2c9f41*****************************************************84e06

One of these malware samples led directly to another operational domain:

  • lynxch2k5xi35j7hlbmwl7d6u2oz4vp2wqp6qkwol624cod3d6iqiyqd.onion

This correlation reinforced the value of using technical artifacts as investigative pivots. Rather than simply cataloguing domains, each malware sample provided another opportunity to uncover infrastructure that was not immediately visible from the group's public-facing services, gradually revealing a far more extensive operational network than the investigation had initially exposed.

The Human Layer

While the infrastructure mapping revealed how Lynx's hidden services were interconnected, the investigation also identified several operational artifacts that offered further insight into how the group communicates with victims and presents itself publicly. Rather than relying on domains alone, these artifacts helped bridge the gap between the group's technical infrastructure and its day-to-day operations.

One of the earliest pivots originated from the historical lynxblog.*** leak page, where the ProtonMail address james*****0@proton.me was first identified. To determine whether additional contact points existed, the domain was further investigated using StealthMole's Dark Web Tracker. This search uncovered two additional email addresses associated with the group's infrastructure:

  • ewik****************8@proton.me
  • martina*************8@proton.me

Unlike standalone contact details, these email addresses appeared repeatedly across multiple artifacts indexed by StealthMole, indicating that they formed part of Lynx's operational communication channels. Their repeated appearance across different records strengthened the association with the group's infrastructure and provided additional indicators for future investigations.

Further examination of these addresses uncovered several copies of the group's ransom note. Beyond outlining payment and negotiation procedures, the note demonstrated how Lynx directs victims toward its communication channels and hidden services. The recovered screenshots also showed martina*******8@proton.me appearing consistently throughout multiple ransom note variants, suggesting that the address was actively used as a victim contact point rather than appearing in a single isolated campaign.

The investigation also revisited several of the group's publicly accessible web pages, including the login and registration portals, to better understand how victims were expected to interact with the platform after initial contact. Combined with the previously identified negotiation portals, these components indicate that Lynx relies on a structured communication workflow in which victims are directed from the leak site to authenticated portals and dedicated contact channels rather than depending exclusively on email correspondence.

To better understand how the group presents itself publicly, a search for "Lynx Ransomware" within StealthMole's Dark Web Tracker uncovered a press release attributed to the operators. In the statement, the group described itself as financially motivated and claimed that it avoids targeting government institutions, hospitals, and non-profit organizations. The release also emphasized negotiation as its preferred method of resolving incidents and portrayed the operation as adhering to its own internal code of conduct.

As with many ransomware groups, however, these statements should be interpreted as self-described messaging rather than independently verified facts. Public declarations of intent often serve to shape perception among victims, affiliates, and the wider cybercriminal ecosystem, and should therefore be considered alongside technical evidence rather than accepted at face value.

The recovered email addresses, ransom notes, negotiation portals, and public statements provide a more complete picture of Lynx's operational identity. While the infrastructure mapping revealed where the group's services reside, these artifacts illustrate how the operators communicate, negotiate, and attempt to define their public image within the ransomware ecosystem.

Conclusion

What began as a review of a single government-sector victim quickly evolved into a broader investigation of Lynx's operational infrastructure. By following a series of technical pivots across StealthMole's Government Monitoring, Ransomware Monitoring, and Dark Web Tracker datasets, the investigation moved beyond the group's public leak site to uncover historical infrastructure, hidden services, malware associations, operational contact channels, and public communications.

Rather than relying on a single source of intelligence, the investigation demonstrated how seemingly unrelated artifacts can be connected to build a more complete picture of a ransomware operation. Historical leak pages provided the first operational pivots, malware intelligence exposed additional hidden services, and recurring communication artifacts revealed how the group manages victim interactions beyond its public-facing website.

Together, these findings highlight the importance of looking beyond victim disclosures when investigating ransomware groups and illustrate how infrastructure-focused analysis can uncover valuable intelligence that may otherwise remain hidden.

Editorial Note

Investigating ransomware groups is rarely a straightforward process. Infrastructure changes over time, hidden services disappear, and public statements often reflect the narrative that threat actors want others to believe rather than independently verifiable facts. Building meaningful intelligence therefore requires careful correlation of historical records, technical artifacts, and operational indicators while maintaining a clear distinction between observed evidence and actor claims.

This investigation demonstrates how StealthMole enables analysts to connect those disparate pieces of information into a coherent picture, allowing investigations to extend well beyond the visible leak site and into the broader infrastructure supporting a ransomware operation.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report