Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

LockBit 5.0 Unveils Cross-Platform Threats for Windows, Linux & ESXi Systems

LockBit 5.0 is a sophisticated ransomware variant that targets Windows, Linux, and VMware ESXi systems. This latest version illustrates the evolving landscape of cyber threats, showcasing how ransomware operators are enhancing their tools to inflict…

LockBit 5.0 is a sophisticated ransomware variant that targets Windows, Linux, and VMware ESXi systems. This latest version illustrates the evolving landscape of cyber threats, showcasing how ransomware operators are enhancing their tools to inflict maximum damage across a range of enterprise environments.

The ransomware operates on a Ransomware-as-a-Service (RaaS) model. In this model, a core team maintains the software while affiliates execute the attacks. This division of labor has industrialized ransomware as a business. Intelligence indicates that the group may be moving towards a consolidation model, potentially aligning with other threats to pool resources and infrastructure.

A notable feature of this release is its specialized focus on VMware ESXi, a system widely used for managing virtual servers. By targeting the hypervisor, attackers can disrupt multiple virtual machines simultaneously.

The LockBit 5.0 ESXi variant follows an automated process:

LockBit 5.0 is a sophisticated ransomware variant that targets Windows, Linux, and VMware ESXi systems.
Aiden Sinclair · Thehackingpost

Validation: The malware verifies it is running on a legitimate ESXi server using specific commands. Virtual Machine Shutdown: To encrypt files successfully, they must not be in use. The malware lists active VMs and powers them off forcibly. Targeted Encryption: Once powered down, the ransomware encrypts critical files such as virtual hard disks, configuration files, and snapshot data.

LockBit 5.0 has adopted the ChaCha20 stream cipher, known for its speed and simplicity, replacing the standard AES encryption. This change allows quick processing of large data volumes, crucial for encrypting extensive server data.

The malware includes a "Fast Mode" feature, encrypting only a fraction of each file initially to render it unusable quickly before a comprehensive encryption pass occurs. It also employs several anti-analysis techniques, making it difficult to detect; at the time of review, only one out of 65 security engines on VirusTotal identified the sample. These techniques include checking for debugging tools and self-deletion post-execution to eliminate traces.

Advertisement

This cross-platform capability and emphasis on speed underscore the importance for organizations to secure not just their Windows endpoints but their entire virtualization infrastructure.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories