logo

19 Shades of LockBit5.0, Inside the Latest Cross-Platform Ransomware: Part 1

ID: 3590fe1c-31fa-59c2-8669-3c83b878cc6d

STIX ID: report--3590fe1c-31fa-59c2-8669-3c83b878cc6d

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
85/100

Date Published: 2026-01-30

Date Updated: 2026-04-28

Author: Mark Tsipershtein, Evgeny Ananin, Nikita Kazymirskyi

...
...

This technical report analyzes 19 cross-platform LockBit 5.0 ransomware samples—focusing on an ESXi-targeting Linux variant and a 32-bit ESXi build—detailing how the malware validates ESXi hosts, enumerates and force-stops VMs via vim-cmd, performs a two-pass ChaCha20-based encryption of VMDK/VMX and related files, supports operator flags (fast mode, logging, exclusions, wiping, self-delete), and includes anti-analysis measures and embedded IOCs such as datastore paths and log locations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.