logo

19 Shades of LockBit 5.0, Inside the Latest Cross-Platform Ransomware: Part 3

ID: 4e04ae5a-19af-5753-8dfd-de36bd77f19c

STIX ID: report--4e04ae5a-19af-5753-8dfd-de36bd77f19c

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
85/100

Date Published: 2026-02-05

Date Updated: 2026-04-28

Author: Alexander Sevtsov, Chen Aviani

...
...

This report provides a detailed technical analysis of the LockBit 5.0 Windows ransomware variant, describing a custom loader that uses process hollowing and disk-mapped API resolution, anti-debugging and geofencing checks, API-hash-driven resolution of functions and service/process names, ETW patching to disable telemetry, COM-based VSS enumeration and deletion, targeted disabling of backup/virtualization/database/security services, RC4-encrypted ransom note handling, command-line options, and embedded IOCs and YARA rules; the analysis highlights enterprise-focused sabotage and notes detection capabilities by security vendors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.