LockBit 5.0 Infrastructure Exposed in New Server, IP, and Domain Leak
The infrastructure of LockBit 5.0 has been exposed, revealing critical details such as the IP address 205.185.116.233 and the domain karma0.xyz, which is hosting the group's latest leak site.
The infrastructure of LockBit 5.0 has been exposed, revealing critical details such as the IP address 205.185.116.233 and the domain karma0.xyz, which is hosting the group's latest leak site.
The server, associated with AS53667 (PONYNET, operated by FranTech Solutions), is utilized by the ransomware group and features a DDoS protection page branded as "LOCKBITS.5.0". This confirms its connection to LockBit's operations.
This exposure occurs as LockBit intensifies its activities with improved malware capabilities.
Researcher Rakesh Krishnan highlighted these findings on December 5, 2025, noting the domain's recent registration and its direct association with LockBit 5.0 activities.
WHOIS records indicate that karma0.xyz was registered on April 12, 2025, with an expiration date in April 2026, using Cloudflare nameservers and Namecheap privacy protection. The contact location is listed as Reykjavik, Iceland.
This exposure occurs as LockBit intensifies its activities with improved malware capabilities.
The domain has a status of client transfer prohibited, suggesting it is secured against unauthorized changes.
Scans of IP 205.185.116.233 reveal multiple open ports, including:
21 - TCP - FTP Server 80 - TCP - Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.0.30 3389 - TCP - RDP (WINDOWS-401V6QI) 5000 - TCP - HTTP 5985 - TCP - WinRM 47001 - TCP - HTTP 49666 - TCP - File Server
Notably, RDP on port 3389 is identified as a high-risk vector, potentially enabling unauthorized access to the Windows host.
LockBit 5.0, which emerged around September 2025, supports Windows, Linux, and ESXi systems. It features randomized file extensions, geolocation-based evasion (excluding Russian systems), and accelerated encryption using XChaCha20.
This exposure highlights ongoing operational security failures for the group. To mitigate potential risks, defenders are advised to block the IP and domain immediately. Researchers should continue monitoring for further leaks.
Based on reporting by Cyber Security News.
