New research examining the technical infrastructure behind several major ransomware operations, including INC Ransom, Lynx, MedusaLocker, and LockBit-related activity, has found that despite operating under different brand names, these groups rely on strikingly similar attack patterns. That consistency matters for anyone trying to understand ransomware, because it means the tools and tactics defenders use to catch one gang often work against several others at the same time.
Shared Infrastructure Behind Different Ransomware Brands
Ransomware is often covered as if each named group is a completely separate criminal enterprise with its own unique playbook. The reality uncovered by this research is messier and, in some ways, more useful for defense. By tracking the infrastructure, meaning the servers, command-and-control channels, and staging systems, used in attacks tied to INC Ransom, Lynx, MedusaLocker, and LockBit, researchers found recurring technical fingerprints across supposedly unrelated campaigns.
This overlap reflects a broader trend already visible elsewhere in the ransomware ecosystem. As covered in reporting on how ransomware groups hit a record 93 active crews, the criminal underground has fragmented into a large number of named operations even as core techniques, and in some cases actual infrastructure, get reused or shared. Ransomware-as-a-service affiliates frequently move between brands, and leaked or resold toolkits mean that different "groups" can end up looking a lot alike under the hood.
Steal First, Encrypt Later: The Double Extortion Standard
One of the clearest patterns to emerge from the research is timing. Before ever locking down a victim's systems, most of the ransomware operations studied quietly exfiltrate sensitive data first. Encryption, the part of the attack that gets noticed because systems suddenly stop working, is often the final step rather than the first one.
This sequencing is the backbone of double extortion: attackers steal data quietly, then encrypt files, then threaten to leak the stolen data publicly if the ransom isn't paid. It gives victims two separate reasons to pay and gives attackers leverage even if a company can restore its systems from backups without paying for a decryption key. This tactic has become so standard that its absence would now be the exception rather than the rule, and it lines up with separate findings on how extortion tactics are shifting as ransom payments hit record lows, pushing groups toward harsher pressure tactics when victims refuse to pay.
Why Early Detection Is Now the Best Defense
Because data theft typically happens well before encryption, there is often a window, sometimes days or weeks, where a compromise is underway but hasn't yet turned into a full-blown crisis. The infrastructure patterns identified in this research give defenders a way to spot that window: recurring command-and-control behavior, staging techniques, and network signatures that show up across INC Ransom, Lynx, MedusaLocker, and LockBit-linked activity.
This matters because the initial break-in is increasingly the weakest link attackers exploit. Separate research covered on this site found that 79% of ransomware incidents start with stolen credentials rather than sophisticated exploits. Combine that with infrastructure that behaves predictably once attackers are inside, and a clearer picture forms: most ransomware attacks aren't unstoppable zero-day masterstrokes. They rely on stolen access and reused tooling, both of which leave detectable traces if organizations know what to look for.
What This Means For You
For everyday users, this research is a reminder that ransomware rarely arrives out of nowhere. It usually follows a stolen password, a phishing email, or an exposed remote access point, and it usually steals data long before anything gets locked or a ransom note appears. For businesses and IT teams, the takeaway is more direct: monitoring for the infrastructure patterns shared across major ransomware families can catch an intrusion during the data theft phase, before encryption ever happens.
For individuals, the practical defense is the same as it's always been: unique passwords, multi-factor authentication, and caution around unexpected login prompts or credential requests. Ransomware groups depend on stolen access to get in the door, so shutting off that access point removes much of their advantage before the more advanced infrastructure tactics ever come into play.
Key Takeaways
- Ransomware groups with different names often share underlying infrastructure and tactics, meaning detection tools built for one gang frequently apply to others.
- Data theft typically happens before encryption, creating a detection window defenders can act on.
- Stolen credentials remain a top entry point, making password hygiene and multi-factor authentication some of the most effective defenses available.
- Organizations should prioritize monitoring for early signs of intrusion, not just ransomware's final, most visible stage.
Understanding how ransomware infrastructure actually works, rather than treating each attack as an isolated event, gives both individuals and organizations a clearer path to catching threats before they escalate. Staying informed about these shared patterns is one of the simplest ways to stay a step ahead.




