19 Shades of LockBit5.0, Inside the Latest Cross-Platform Ransomware: Part 1
ID: 3590fe1c-31fa-59c2-8669-3c83b878cc6d
STIX ID: report--3590fe1c-31fa-59c2-8669-3c83b878cc6d
Feed Name: LevelBlue SpiderLabs Blog
Date Published: 2026-01-30
Date Updated: 2026-04-28
Author: Mark Tsipershtein, Evgeny Ananin, Nikita Kazymirskyi
This technical report analyzes 19 cross-platform LockBit 5.0 ransomware samples—focusing on an ESXi-targeting Linux variant and a 32-bit ESXi build—detailing how the malware validates ESXi hosts, enumerates and force-stops VMs via vim-cmd, performs a two-pass ChaCha20-based encryption of VMDK/VMX and related files, supports operator flags (fast mode, logging, exclusions, wiping, self-delete), and includes anti-analysis measures and embedded IOCs such as datastore paths and log locations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
