LockBit 5.0 Emerges: Cross-Platform Ransomware Now Targeting Windows, Linux, and ESXi Systems
ID: be3271b2-9108-52be-9034-658d70cb4fb7
STIX ID: report--be3271b2-9108-52be-9034-658d70cb4fb7
Feed Name: GBHackers
**LockBit 5.0** is an actively deployed, cross-platform ransomware family targeting Windows, Linux and ESXi/virtualized environments that combines fast XChaCha20/Curve25519 encryption with strong anti-analysis and anti-forensic features; affiliates using a RaaS double-extortion model have exposed at least ~60 victims across sectors, and the variants include virtualization-specific functions to cripple VMs and wipe free space, underscoring a high enterprise impact and persistent criminal infrastructure reuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
