LockBit 5.0 Unveils Cross-Platform Threats for Windows, Linux & ESXi Systems
LockBit 5.0 is a sophisticated ransomware variant that targets Windows, Linux, and VMware ESXi systems. This latest version illustrates the evolving landscape of cyber threats, showcasing how ransomware operators are enhancing their tools to inflict…
LockBit 5.0 is a sophisticated ransomware variant that targets Windows, Linux, and VMware ESXi systems. This latest version illustrates the evolving landscape of cyber threats, showcasing how ransomware operators are enhancing their tools to inflict maximum damage across a range of enterprise environments.
The ransomware operates on a Ransomware-as-a-Service (RaaS) model. In this model, a core team maintains the software while affiliates execute the attacks. This division of labor has industrialized ransomware as a business. Intelligence indicates that the group may be moving towards a consolidation model, potentially aligning with other threats to pool resources and infrastructure.
A notable feature of this release is its specialized focus on VMware ESXi, a system widely used for managing virtual servers. By targeting the hypervisor, attackers can disrupt multiple virtual machines simultaneously.
The LockBit 5.0 ESXi variant follows an automated process:
LockBit 5.0 is a sophisticated ransomware variant that targets Windows, Linux, and VMware ESXi systems.
Validation: The malware verifies it is running on a legitimate ESXi server using specific commands. Virtual Machine Shutdown: To encrypt files successfully, they must not be in use. The malware lists active VMs and powers them off forcibly. Targeted Encryption: Once powered down, the ransomware encrypts critical files such as virtual hard disks, configuration files, and snapshot data.
LockBit 5.0 has adopted the ChaCha20 stream cipher, known for its speed and simplicity, replacing the standard AES encryption. This change allows quick processing of large data volumes, crucial for encrypting extensive server data.
The malware includes a "Fast Mode" feature, encrypting only a fraction of each file initially to render it unusable quickly before a comprehensive encryption pass occurs. It also employs several anti-analysis techniques, making it difficult to detect; at the time of review, only one out of 65 security engines on VirusTotal identified the sample. These techniques include checking for debugging tools and self-deletion post-execution to eliminate traces.
This cross-platform capability and emphasis on speed underscore the importance for organizations to secure not just their Windows endpoints but their entire virtualization infrastructure.
Based on reporting by GBHackers.
