Skip to main content
← Back to Demos
Malware intermediate · 15 min

ALPHV Rebrands as Lynx: Double-Extortion Ransomware Payloads Flagged by Metascan (2026-08-30 CISO Daily Digest)

The 2026-08-30 CISO Daily Digest reported that ALPHV — the Black Basta-affiliated ransomware gang behind the 2024 Change Healthcare attack, which claimed to have disbanded in June 2026 following law-enforcement pressure — has re-established operations under the new moniker Lynx, standing up fresh C2 infrastructure and dedicated data-exfiltration servers. Healthcare and manufacturing organizations report renewed double-extortion campaigns (encryption plus stolen-data leaks) with over US$200M in claimed losses year-to-date, tracked by Recorded Future and BleepingComputer. For defenders, the practical reality of any rebrand is that the playbook stays the same: a ransomware binary and its staged payloads must still cross the file boundary — typically as a phished archive or document attachment — before they can reach a disk. This demo reproduces that crossing safely: the archive ships EICAR test files standing in for the Lynx binary and staged payloads — a classic eicar.com, an eicar.txt, a compiled Windows PE embedding the EICAR string, and a ZIP-wrapped EICAR — alongside a clean control file (no real malware, nothing destructive). MetaDefender Metascan runs 30+ anti-malware engines (including ClamAV) over every variant in a single pass and flags them all, showing how a double-extortion encryption campaign is stopped at the file boundary — at the gateway, before Lynx's payload ever touches a hospital or factory endpoint (MITRE ATT&CK T1486 Data Encrypted for Impact).

Attack Technique

Data encrypted for impact — double-extortion ransomware (ALPHV/Lynx) payloads crossing the file boundary as EICAR stand-ins, flagged by multiscanning before execution (T1486)

MITRE ATT&CK

T1486 ↗

Platforms

linux

File Types

.com.exe.txt.zip

MetaDefender Capabilities

Metascan

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---