Beyond the Leak Site: Uncovering Lynx Ransomware's Infrastructure
Ransomware operations have evolved well beyond encrypting files and demanding payment. Many now function as structured criminal enterprises, maintaining dedicated leak sites, communication portals, and supporting infrastructure designed to pressure victims, manage negotiations, and reinforce their public presence. While these websites often become the most visible part of a ransomware operation, they rarely tell the full story.
Lynx is one such group. Since emerging on the ransomware landscape, it has established an online presence that extends beyond publishing victim information. Like many modern ransomware operations, its infrastructure consists of multiple interconnected components that each serve a distinct purpose, offering valuable insight into how the group presents itself and supports its activities.
This report explores Lynx's publicly accessible infrastructure through a technical investigation conducted using StealthMole. By following infrastructure pivots, examining hidden services, and correlating findings across multiple StealthMole datasets, the investigation moves beyond the group's leak site to build a broader picture of its operational footprint. Rather than focusing on individual attacks or victim disclosures, the report examines the digital infrastructure surrounding the operation and the intelligence that can be uncovered by following those connections.
Behind the Curtain
The investigation began in StealthMole's Government Monitoring module, where a search for "Lynx" returned 8 government-sector organizations that had been listed by the group. The most recent entry was the Talbot County Department of Emergency Services (DES), whose disclosure page included a description of the organization, its reported annual revenue, and the date the listing was published. While the victim itself was not the focus of this investigation, the listing provided an entry point into Lynx's ecosystem and established a starting point for exploring the infrastructure supporting its operations.
- http://lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion/leaks
To understand the broader scope of the group, the investigation then shifted to StealthMole's Ransomware Monitoring module. A further search of Lynx revealed a significantly larger operational footprint, with 397 victims indexed between July 2024 and August 2026. The volume of disclosures demonstrated that the Talbot County incident was not an isolated event but part of an active ransomware campaign that had persisted for more than two years. More importantly, the historical records offered an opportunity to look beyond recent activity and trace how the group's infrastructure had evolved over time.
Rather than concentrating on the latest disclosures alone, earlier victim listings were examined to identify infrastructure that might no longer be visible through the current leak site. One of the earliest indexed entries, published in August 2024, pointed to a different leak page hosted at:
- http://lynxblog.******/leaks/66a***********331
This historical listing proved particularly valuable. In addition to the victim information, it exposed several operational artifacts that were absent from more recent disclosures, including the ProtonMail address james*******0@proton.me and a dedicated Tor-based negotiation portal:
- http://lynxch*********************************qiyqd.onion/login
Victims were also instructed to register using an unique identifier before initiating negotiations. These details suggested that the historical leak page offered far more than a record of a past victim. It provided the first tangible links to the group's operational infrastructure and presented several new avenues for investigation.
- 66*****************cb4e
Inside the Infrastructure
With historical artifacts pointing towards multiple operational components, the investigation turned to Lynx's current infrastructure to determine how the group maintained its public presence and whether traces of its wider ecosystem remained accessible.
- lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion
A review of the site confirmed that it remained active at the time of the investigation. Its homepage followed the structure commonly adopted by modern ransomware operations, providing access to sections dedicated to News, Leaks, and Report, while continuing to publish victim disclosures through an actively maintained leak portal. StealthMole's historical records showed that the hidden service was first observed on 20 August 2024 and remained active as of 11 August 2026, demonstrating that the infrastructure had been operational for nearly two years.
The leak portal itself contained the latest victim disclosures. Alongside each victim listing, the site published organizational descriptions, reported revenue, publication dates, and supporting proof files, reflecting the group's continued use of public disclosures as a means of pressuring victims during negotiations.
Rather than stopping at the homepage, the investigation expanded to examine the hidden service itself. Several publicly accessible pages were identified, each providing a clearer picture of how the platform was structured.
Component | URL |
Login Portal | http://lynxchat***********knad.onion/main/chat |
Registration Portal | http://lynxchat************knad.onion/register |
Chat Interface | http://lynxchat***********knad.onion/main/chat |
Server Status | http://lynxchat*******knad.onion/server-status |
The login interface required registered credentials, while the registration page prompted users to enter a unique identifier and password before creating an account. Combined with the dedicated chat interface, these pages indicate that the platform was designed to support authenticated victim communications rather than relying solely on email exchanges. An attempt to access the /server-status endpoint returned a 404 Page Not Found response, suggesting that the endpoint was either unavailable or intentionally inaccessible during the investigation.
The infrastructure also exposed additional technical metadata through StealthMole. The hidden service was identified as running nginx/1.27.5 While these metadata points do not independently reveal the group's operations, they provide additional artifacts that can be correlated with other datasets during an infrastructure investigation.
Connecting the Dots
With the current leak site confirmed to be active, the investigation shifted from examining the visible infrastructure to exploring the technical artifacts associated with it. Rather than relying solely on what could be observed through the website itself, StealthMole was used to pivot from the hidden service into related malware intelligence, allowing the investigation to uncover connections that would not have been apparent from the leak site alone.
- lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion
Searching the current leak site, within StealthMole's Dark Web Tracker revealed 37 malware hashes associated with the domain. Rather than treating these as isolated indicators, each hash was investigated individually to determine whether it could provide additional insight into the group's operational infrastructure.
- 0212*******************************************************7a5eb
- 71db*******************************************************a0834
- c587*******************************************************6d633
- f85e*******************************************************0e619
- 820e*******************************************************36f8a
- 582e*******************************************************2fffe
- 31de*******************************************************d5193
- 5da4*******************************************************83040
- bb4e*******************************************************f600a
- f71f*******************************************************62787
- 8090*******************************************************0c441
- 97c8*******************************************************2ba00
- 8569*******************************************************f5683
- 432f*******************************************************29c66
- d20c*******************************************************999f9
- 468e*******************************************************89d6a
- 0315*******************************************************21663
- 589f*******************************************************21a23
- 571f*******************************************************6cf8b
- 551e*******************************************************ec386
- 9a47*******************************************************a3896
- ecbf*******************************************************f6e49
- f9bb*******************************************************d56b7
- 4e5b*******************************************************66412
- c3b5*******************************************************24a18
- 4ad4*******************************************************06ac4
- 90ac*******************************************************cf7b8
- ac68*******************************************************5b43f
- dac3*******************************************************c94ed
- cf7c*******************************************************7ac9c
- 6486*******************************************************0313a
- 0fb2*******************************************************1da93
- ac50*******************************************************e9b60
- dcba*******************************************************359cc
- 4fbb*******************************************************4763b
- 5533*******************************************************a931d
- 1a01*******************************************************6ced0
One hash, in particular, proved especially valuable:
- 4fb****************************************************763b
Using this artifact as a pivot uncovered a much broader network of Lynx-associated hidden services. The hash was linked to 14 separate Tor domains, consisting of both leak portals and negotiation portals.
Associated Leak Sites
Domain | Status |
lynxblogco7r37jt7p5wrmfxzqze7ghxw6rihzkqc455qluacwotciyd.onion | Inactive |
lynxblog************************************2sjyd.onion | Active |
lynxblog***********************************2csyad.onion | Active |
lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion | Inactive |
lynxblog************************************omjad.onion | Active |
lynxblog***********************************z3xwqd.onion | Active |
lynxblog**********************************ngrfoid.onion | Active |
Associated Negotiation Portals
Domain | Status |
lynxchat**********************************dbsgmyd.onion | Active |
lynxchatde4spv5x6xlwxf47jdo7wtwwgikdoeroxamphu3e7xx5doqd.onion | Inactive |
lynxchatdy3tgcuijsqofhssopcepirjfq2f4pvb5qd4un4dhqyxswqd.onion | Inactive |
lynxchat***********************************6quxqd.onion | Active |
lynxchatfw4rgsclp4567i4llkqjr2kltaumwwobxdik3qa2oorrknad.onion | Inactive |
lynxchatly4zludmhmi75jrwhycnoqvkxb4prohxmyzf4euf5gjxroad.onion | Inactive |
lynxchatohmppv6au67lloc2vs6chy7nya7dsu2hhs55mcjxp2joglad.onion | Inactive |
This single pivot expanded the investigation well beyond the original leak site, revealing multiple generations of Lynx infrastructure that included both active and inactive hidden services. Instead of a standalone website, the findings pointed towards an ecosystem of interconnected domains supporting different aspects of the group's operation.
The investigation continued by exploring additional Lynx-related domains identified through StealthMole, uncovering a further 16 hidden services sharing the group's naming convention. While their specific functions could not be determined from the available evidence, they collectively demonstrated that Lynx maintained a significantly broader Tor footprint than was immediately visible through its public leak site.
Among the additional infrastructure identified were:
- lynx2*************************************fqiqd.onion
- lynxa*************************************5daqd.onion
- lynxo**************************************2oqd.onion
- lynx2*************************************626yd.onion
- lynxb************************************z3vvyd.onion
- lynxk*************************************xc3ad.onion
- lynxa*************************************whead.onion
- lynxh*************************************feuid.onion
- lynxc************************************v2pxyd.onion
while several additional domains were observed in an inactive state, suggesting that portions of the infrastructure had either been retired or replaced over time.
The infrastructure mapping did not end there. A further pivot into the hidden service
- lynxbllrfr5262yvbgtqoyq76s7mpztcqkv6tjjxgpilpma7nyoeohyd.onion
identified three additional malware samples associated with the domain:
- 9e565d*****************************************************345da
- 730f82*****************************************************a753c
- 2c9f41*****************************************************84e06
One of these malware samples led directly to another operational domain:
- lynxch2k5xi35j7hlbmwl7d6u2oz4vp2wqp6qkwol624cod3d6iqiyqd.onion
This correlation reinforced the value of using technical artifacts as investigative pivots. Rather than simply cataloguing domains, each malware sample provided another opportunity to uncover infrastructure that was not immediately visible from the group's public-facing services, gradually revealing a far more extensive operational network than the investigation had initially exposed.
The Human Layer
While the infrastructure mapping revealed how Lynx's hidden services were interconnected, the investigation also identified several operational artifacts that offered further insight into how the group communicates with victims and presents itself publicly. Rather than relying on domains alone, these artifacts helped bridge the gap between the group's technical infrastructure and its day-to-day operations.
One of the earliest pivots originated from the historical lynxblog.*** leak page, where the ProtonMail address james*****0@proton.me was first identified. To determine whether additional contact points existed, the domain was further investigated using StealthMole's Dark Web Tracker. This search uncovered two additional email addresses associated with the group's infrastructure:
- ewik****************8@proton.me
- martina*************8@proton.me
Unlike standalone contact details, these email addresses appeared repeatedly across multiple artifacts indexed by StealthMole, indicating that they formed part of Lynx's operational communication channels. Their repeated appearance across different records strengthened the association with the group's infrastructure and provided additional indicators for future investigations.
Further examination of these addresses uncovered several copies of the group's ransom note. Beyond outlining payment and negotiation procedures, the note demonstrated how Lynx directs victims toward its communication channels and hidden services. The recovered screenshots also showed martina*******8@proton.me appearing consistently throughout multiple ransom note variants, suggesting that the address was actively used as a victim contact point rather than appearing in a single isolated campaign.
The investigation also revisited several of the group's publicly accessible web pages, including the login and registration portals, to better understand how victims were expected to interact with the platform after initial contact. Combined with the previously identified negotiation portals, these components indicate that Lynx relies on a structured communication workflow in which victims are directed from the leak site to authenticated portals and dedicated contact channels rather than depending exclusively on email correspondence.
To better understand how the group presents itself publicly, a search for "Lynx Ransomware" within StealthMole's Dark Web Tracker uncovered a press release attributed to the operators. In the statement, the group described itself as financially motivated and claimed that it avoids targeting government institutions, hospitals, and non-profit organizations. The release also emphasized negotiation as its preferred method of resolving incidents and portrayed the operation as adhering to its own internal code of conduct.
As with many ransomware groups, however, these statements should be interpreted as self-described messaging rather than independently verified facts. Public declarations of intent often serve to shape perception among victims, affiliates, and the wider cybercriminal ecosystem, and should therefore be considered alongside technical evidence rather than accepted at face value.
The recovered email addresses, ransom notes, negotiation portals, and public statements provide a more complete picture of Lynx's operational identity. While the infrastructure mapping revealed where the group's services reside, these artifacts illustrate how the operators communicate, negotiate, and attempt to define their public image within the ransomware ecosystem.
Conclusion
What began as a review of a single government-sector victim quickly evolved into a broader investigation of Lynx's operational infrastructure. By following a series of technical pivots across StealthMole's Government Monitoring, Ransomware Monitoring, and Dark Web Tracker datasets, the investigation moved beyond the group's public leak site to uncover historical infrastructure, hidden services, malware associations, operational contact channels, and public communications.
Rather than relying on a single source of intelligence, the investigation demonstrated how seemingly unrelated artifacts can be connected to build a more complete picture of a ransomware operation. Historical leak pages provided the first operational pivots, malware intelligence exposed additional hidden services, and recurring communication artifacts revealed how the group manages victim interactions beyond its public-facing website.
Together, these findings highlight the importance of looking beyond victim disclosures when investigating ransomware groups and illustrate how infrastructure-focused analysis can uncover valuable intelligence that may otherwise remain hidden.
Editorial Note
Investigating ransomware groups is rarely a straightforward process. Infrastructure changes over time, hidden services disappear, and public statements often reflect the narrative that threat actors want others to believe rather than independently verifiable facts. Building meaningful intelligence therefore requires careful correlation of historical records, technical artifacts, and operational indicators while maintaining a clear distinction between observed evidence and actor claims.
This investigation demonstrates how StealthMole enables analysts to connect those disparate pieces of information into a coherent picture, allowing investigations to extend well beyond the visible leak site and into the broader infrastructure supporting a ransomware operation.
To access the unmasked report or full details, please reach out to us separately.
Contact us: support@stealthmole.com
Labels: Featured, Ransomware