Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

LockBit 5.0 Infrastructure Exposed as Hackers Leak Critical Server Data

Security researchers have identified critical infrastructure details for the LockBit 5.0 ransomware operation. Key findings include the IP address 205.185.116.233 and the domain karma0.xyz, which serves as the group's latest leak site. This reveals…

Security researchers have identified critical infrastructure details for the LockBit 5.0 ransomware operation. Key findings include the IP address 205.185.116.233 and the domain karma0.xyz, which serves as the group's latest leak site. This reveals significant operational security issues for the cybercriminal organization.

On Tue, Dec 5, 2025, cybersecurity researcher Rakesh Krishnan disclosed these details. The implicated server is hosted under AS53667 (PONYNET, managed by FranTech Solutions), a network known for its use in illicit activities.

The server displays a DDoS protection page labeled "LOCKBITS.5.0," confirming its connection to the ransomware group's activities. WHOIS records show karma0.xyz was registered on Apr 12, 2025, with an expiration date in Apr 2026. The domain uses Cloudflare nameservers and Namecheap privacy protection, listing Reykjavik, Iceland, as the contact location. Its status as client transfer prohibited indicates an effort to retain control amid scrutiny.

Security scans revealed multiple open ports on the exposed server, posing significant security risks. Port 21 runs an FTP server, while port 80 operates Apache/2.4.58 (Win64) with OpenSSL/3.1.3 and PHP/8.0.30. Port 3389 exposes Remote Desktop Protocol (RDP) on a Windows host named WINDOWS-401V6QI, presenting a high-risk vector for unauthorized access. Additional open ports include 5000 and 5985 for HTTP and WinRM, respectively; port 47001 for HTTP; and port 49666 for a file server.

Security researchers have identified critical infrastructure details for the LockBit 5.0 ransomware operation.
Megan Forbes · Thehackingpost

LockBit 5.0 emerged around Sep 2025, with enhanced malware capabilities supporting Windows, Linux, and ESXi systems. The ransomware features randomized file extensions, skips Russian systems based on geolocation, and accelerates encryption using XChaCha20 algorithms.

Researchers noted that the group incorporates Smokeloader into its attack campaigns. Security defenders are advised to block the exposed IP address and domain immediately. Organizations can monitor these indicators for potential compromise attempts.

Advertisement

This exposure underscores ongoing operational security failures for LockBit, despite multiple disruptions by law enforcement. The group continues to demonstrate resilience, maintaining active ransomware operations targeting organizations globally.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories