Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

LockBit 5.0 Targets Windows, Linux, and ESXi Systems in Ongoing Attacks

In early 2024, Operation Cronos disrupted the activities of the LockBit ransomware group. However, by September 2025, the group has resurfaced with significant updates, notably the LockBit 5.0 variant, which accounted for half of the attacks identified…

In early 2024, Operation Cronos disrupted the activities of the LockBit ransomware group. However, by September 2025, the group has resurfaced with significant updates, notably the LockBit 5.0 variant, which accounted for half of the attacks identified during the month. This resurgence has targeted organizations across Western Europe, the Americas, and Asia, highlighting the group's extensive reach and reactivated affiliate network.

Technical Evolution and Multi-Platform Targeting

LockBit 5.0 introduces several enhancements designed to increase impact and reduce detection. The variant supports Windows, Linux, and ESXi environments, enabling attacks on hybrid and virtualized infrastructure. Approximately 80% of attacks targeted Windows systems, with the remaining 20% focused on ESXi and Linux environments.

Improvements in anti-analysis mechanisms, optimized encryption routines, and randomized file extensions complicate detection and response. Additionally, the affiliate control panel has been upgraded, providing enhanced management with individualized credentials. Affiliates must deposit approximately $500 in Bitcoin to access the control panel and encryptor packages.

Updated ransom notes identify the variant as LockBit 5.0, including personalized negotiation links with a standard 30-day deadline before data publication.

In early 2024, Operation Cronos disrupted the activities of the LockBit ransomware group.
Ben Emerson · Thehackingpost

The reemergence of LockBit presents a challenge for the cybersecurity industry, demonstrating the resilience of sophisticated ransomware operations. The group’s comeback suggests that the September victims may only represent the initial phase of a broader campaign.

Organizations are urged to prioritize multi-layered defenses that cover network perimeter protection, endpoint threat prevention, and detection capabilities across all infrastructure types. LockBit's capability to compromise Windows, Linux, and virtualization platforms necessitates comprehensive security strategies.

Advertisement

For more information, visit Check Point Research .

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories