LockBit 5.0 Targets Windows, Linux, and ESXi Systems in Ongoing Attacks
In early 2024, Operation Cronos disrupted the activities of the LockBit ransomware group. However, by September 2025, the group has resurfaced with significant updates, notably the LockBit 5.0 variant, which accounted for half of the attacks identified…
In early 2024, Operation Cronos disrupted the activities of the LockBit ransomware group. However, by September 2025, the group has resurfaced with significant updates, notably the LockBit 5.0 variant, which accounted for half of the attacks identified during the month. This resurgence has targeted organizations across Western Europe, the Americas, and Asia, highlighting the group's extensive reach and reactivated affiliate network.
Technical Evolution and Multi-Platform Targeting
LockBit 5.0 introduces several enhancements designed to increase impact and reduce detection. The variant supports Windows, Linux, and ESXi environments, enabling attacks on hybrid and virtualized infrastructure. Approximately 80% of attacks targeted Windows systems, with the remaining 20% focused on ESXi and Linux environments.
Improvements in anti-analysis mechanisms, optimized encryption routines, and randomized file extensions complicate detection and response. Additionally, the affiliate control panel has been upgraded, providing enhanced management with individualized credentials. Affiliates must deposit approximately $500 in Bitcoin to access the control panel and encryptor packages.
Updated ransom notes identify the variant as LockBit 5.0, including personalized negotiation links with a standard 30-day deadline before data publication.
In early 2024, Operation Cronos disrupted the activities of the LockBit ransomware group.
The reemergence of LockBit presents a challenge for the cybersecurity industry, demonstrating the resilience of sophisticated ransomware operations. The group’s comeback suggests that the September victims may only represent the initial phase of a broader campaign.
Organizations are urged to prioritize multi-layered defenses that cover network perimeter protection, endpoint threat prevention, and detection capabilities across all infrastructure types. LockBit's capability to compromise Windows, Linux, and virtualization platforms necessitates comprehensive security strategies.
For more information, visit Check Point Research .
Based on reporting by GBHackers.
