LockBit strikes with new 5.0 version, targeting Windows, Linux and ESXI systems
ID: 633e6cbd-317f-5d82-84a3-38f174eaf4ce
STIX ID: report--633e6cbd-317f-5d82-84a3-38f174eaf4ce
Feed Name: TRU Security by Acronis
Acronis TRU analyzed LockBit 5.0, a multi-platform ransomware family (Windows, Linux, ESXi) that uses XChaCha20 and Curve25519 for encryption, employs advanced defense-evasion and anti-analysis techniques (packing, DLL unhooking, process hollowing, ETW patching), conducts double-extortion via data exfiltration and maintains a public leak site with active victim listings; Linux/ESXi variants target virtualization including Proxmox/VMFS and include free-space wiping, and the report includes IoCs and links to suspected infrastructure reuse with SmokeLoader.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
