logo

LockBit 5.0 Introduces New Features: ChaCha20 Encryption, Stealthy Installation, and Anti-Analysis to Target Windows, Linux, and ESXi Environments

ID: c3c86f00-a0a2-5e42-9e5a-692e62cfef44

STIX ID: report--c3c86f00-a0a2-5e42-9e5a-692e62cfef44

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
80/100

Date Published: 2026-01-30

Date Updated: 2026-04-28

Author: SpiderLabs Researcher

...
...

LockBit 5.0 is a highly evolved, cross-platform ransomware-as-a-service variant that adopts ChaCha20 encryption and multiple stealthy, modular techniques—including in-memory execution, anti-analysis/ETW patching, a wiper component, targeted destruction of backup/virtualization infrastructure, and use of hard-to-recover hashing for API/process names—to maximize damage and evade detection; the report provides technical analysis of samples, IOCs, MITRE ATT&CK mapping, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.