LockBit’s New 5.0 Version Attacking Windows, Linux and ESXI Systems
LockBit ransomware has released version 5.0, which targets multiple operating systems, including Windows, Linux, and ESXi. This update, launched in September 2025, marks a significant enhancement in the ransomware's capabilities.
LockBit ransomware has released version 5.0, which targets multiple operating systems, including Windows, Linux, and ESXi. This update, launched in September 2025, marks a significant enhancement in the ransomware's capabilities.
LockBit 5.0 operates as a ransomware-as-a-service , utilizing a double-extortion model that encrypts files and exfiltrates data. It is particularly focused on the U.S. business sector, with private companies comprising about 67% of its victims. Other affected sectors include manufacturing, healthcare, education, financial services, and government agencies.
Since December 2025, 60 entries have been recorded on the LockBit data leak site, indicating the campaign's extensive impact.
The ransomware is notable for its compatibility with all versions of Proxmox, a widely adopted open-source virtualization platform. LockBit 5.0 shares features with its predecessor but offers advanced defense evasion and faster encryption.
LockBit ransomware has released version 5.0, which targets multiple operating systems, including Windows, Linux, and ESXi.
The Windows version uses sophisticated anti-analysis techniques, including packing, DLL unhooking, and process hollowing, while the Linux and ESXi versions encrypt their strings to avoid detection. All versions utilize XChaCha20 for symmetric encryption and Curve25519 for asymmetric encryption, with each encrypted file receiving a unique 16-character extension.
Advanced Evasion and Persistence Mechanisms
LockBit 5.0 employs complex evasion tactics, such as Mixed Boolean-Arithmetic obfuscation and return-address dependent hashing. It performs geolocation checks to avoid systems in post-Soviet countries and uses process hollowing by injecting into Windows defrag.exe. After encryption, it patches the EtwEventWrite function and clears event logs, removing traces of its activity.
The ransomware's infrastructure shares ties with SmokeLoader malware operations, suggesting possible collaboration between cybercriminal groups.
Organizations are advised to implement multi-layered security controls, regular offline backups, network segmentation, endpoint detection and response solutions, and timely patch management. Employee security awareness training is essential to mitigate phishing threats. System administrators should monitor for unusual process behavior, unexpected file encryption, and attempts to disable security logging.
Based on reporting by Cyber Security News.
