LockBit’s New 5.0 Version Attacking Windows, Linux and ESXI Systems
ID: 93e9163c-cd7d-5e9e-9454-9c0773248ff4
STIX ID: report--93e9163c-cd7d-5e9e-9454-9c0773248ff4
Feed Name: cybersecurityNews.com
LockBit 5.0 (released Sept 2025) is a major upgrade to the LockBit ransomware family that supports Windows, Linux and ESXi (including advertised Proxmox support), uses a double‑extortion model, and targets multiple sectors—primarily U.S. businesses—with at least 60 victims listed on its leak site; the variants use XChaCha20/Curve25519 encryption and include advanced evasion and persistence techniques (packing, DLL unhooking, process hollowing, ETW patching, log clearing), and defenders are advised to deploy layered controls (offline backups, segmentation, EDR, patching, and user training).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
