logo

New LockBit 5.0 Targets Windows, Linux, ESXi

ID: 2c2f46f9-6313-5a7f-b79e-180d463b2f17

STIX ID: report--2c2f46f9-6313-5a7f-b79e-180d463b2f17

Feed Name: TrendAI Security Blog

Threat Score
85/100

Date Published: 2026-01-01

Date Updated: 2026-08-06

...
...

Trend Research details LockBit 5.0 as an active, cross-platform ransomware family (Windows, Linux, ESXi) that uses heavy packing/obfuscation, in-memory DLL reflection loading, ETW patching, service termination, event log clearing, randomized 16-character file extensions, and geopolitical safeguards; the ESXi variant can encrypt entire virtual infrastructures, amplifying impact. The report provides command-line parameter mappings, IOCs, hunting queries, and code-comparison evidence linking 5.0 to LockBit 4.0, and recommends enhanced cross-platform and virtualization protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.