logo

LockBit strikes with new 5.0 version, targeting Windows, Linux and ESXI systems

ID: 633e6cbd-317f-5d82-84a3-38f174eaf4ce

STIX ID: report--633e6cbd-317f-5d82-84a3-38f174eaf4ce

Feed Name: TRU Security by Acronis

Threat Score
78/100

Date Published: 2026-02-12

Date Updated: 2026-07-24

...
...

Acronis TRU analyzed LockBit 5.0, a multi-platform ransomware family (Windows, Linux, ESXi) that uses XChaCha20 and Curve25519 for encryption, employs advanced defense-evasion and anti-analysis techniques (packing, DLL unhooking, process hollowing, ETW patching), conducts double-extortion via data exfiltration and maintains a public leak site with active victim listings; Linux/ESXi variants target virtualization including Proxmox/VMFS and include free-space wiping, and the report includes IoCs and links to suspected infrastructure reuse with SmokeLoader.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.