LockBit 5.0 Infrastructure Exposed as Hackers Leak Critical Server Data
Security researchers have identified critical infrastructure details for the LockBit 5.0 ransomware operation. Key findings include the IP address 205.185.116.233 and the domain karma0.xyz, which serves as the group's latest leak site. This reveals…
Security researchers have identified critical infrastructure details for the LockBit 5.0 ransomware operation. Key findings include the IP address 205.185.116.233 and the domain karma0.xyz, which serves as the group's latest leak site. This reveals significant operational security issues for the cybercriminal organization.
On Tue, Dec 5, 2025, cybersecurity researcher Rakesh Krishnan disclosed these details. The implicated server is hosted under AS53667 (PONYNET, managed by FranTech Solutions), a network known for its use in illicit activities.
The server displays a DDoS protection page labeled "LOCKBITS.5.0," confirming its connection to the ransomware group's activities. WHOIS records show karma0.xyz was registered on Apr 12, 2025, with an expiration date in Apr 2026. The domain uses Cloudflare nameservers and Namecheap privacy protection, listing Reykjavik, Iceland, as the contact location. Its status as client transfer prohibited indicates an effort to retain control amid scrutiny.
Security scans revealed multiple open ports on the exposed server, posing significant security risks. Port 21 runs an FTP server, while port 80 operates Apache/2.4.58 (Win64) with OpenSSL/3.1.3 and PHP/8.0.30. Port 3389 exposes Remote Desktop Protocol (RDP) on a Windows host named WINDOWS-401V6QI, presenting a high-risk vector for unauthorized access. Additional open ports include 5000 and 5985 for HTTP and WinRM, respectively; port 47001 for HTTP; and port 49666 for a file server.
Security researchers have identified critical infrastructure details for the LockBit 5.0 ransomware operation.
LockBit 5.0 emerged around Sep 2025, with enhanced malware capabilities supporting Windows, Linux, and ESXi systems. The ransomware features randomized file extensions, skips Russian systems based on geolocation, and accelerates encryption using XChaCha20 algorithms.
Researchers noted that the group incorporates Smokeloader into its attack campaigns. Security defenders are advised to block the exposed IP address and domain immediately. Organizations can monitor these indicators for potential compromise attempts.
This exposure underscores ongoing operational security failures for LockBit, despite multiple disruptions by law enforcement. The group continues to demonstrate resilience, maintaining active ransomware operations targeting organizations globally.
Based on reporting by GBHackers.
