Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

LockBit 5.0 Infrastructure Exposed in New Server, IP, and Domain Leak

The infrastructure of LockBit 5.0 has been exposed, revealing critical details such as the IP address 205.185.116.233 and the domain karma0.xyz, which is hosting the group's latest leak site.

The infrastructure of LockBit 5.0 has been exposed, revealing critical details such as the IP address 205.185.116.233 and the domain karma0.xyz, which is hosting the group's latest leak site.

The server, associated with AS53667 (PONYNET, operated by FranTech Solutions), is utilized by the ransomware group and features a DDoS protection page branded as "LOCKBITS.5.0". This confirms its connection to LockBit's operations.

This exposure occurs as LockBit intensifies its activities with improved malware capabilities.

Researcher Rakesh Krishnan highlighted these findings on December 5, 2025, noting the domain's recent registration and its direct association with LockBit 5.0 activities.

WHOIS records indicate that karma0.xyz was registered on April 12, 2025, with an expiration date in April 2026, using Cloudflare nameservers and Namecheap privacy protection. The contact location is listed as Reykjavik, Iceland.

This exposure occurs as LockBit intensifies its activities with improved malware capabilities.
Rachel Green · Thehackingpost

The domain has a status of client transfer prohibited, suggesting it is secured against unauthorized changes.

Scans of IP 205.185.116.233 reveal multiple open ports, including:

21 - TCP - FTP Server 80 - TCP - Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.0.30 3389 - TCP - RDP (WINDOWS-401V6QI) 5000 - TCP - HTTP 5985 - TCP - WinRM 47001 - TCP - HTTP 49666 - TCP - File Server

Notably, RDP on port 3389 is identified as a high-risk vector, potentially enabling unauthorized access to the Windows host.

Advertisement

LockBit 5.0, which emerged around September 2025, supports Windows, Linux, and ESXi systems. It features randomized file extensions, geolocation-based evasion (excluding Russian systems), and accelerated encryption using XChaCha20.

This exposure highlights ongoing operational security failures for the group. To mitigate potential risks, defenders are advised to block the IP and domain immediately. Researchers should continue monitoring for further leaks.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories