New LockBit 5.0 Ransomware Variant Attacking Windows, Linux, and ESXi Systems
Following significant law enforcement activity in February 2024, the LockBit ransomware group has launched a new version, LockBit 5.0, coinciding with its sixth anniversary.
Following significant law enforcement activity in February 2024, the LockBit ransomware group has launched a new version, LockBit 5.0, coinciding with its sixth anniversary.
Trend Micro has analyzed binaries for Windows, Linux, and VMware ESXi, confirming the group's ongoing focus on cross-platform attacks aimed at disrupting entire enterprise networks.
The emergence of these variants in early September 2025 indicates a notable evolution. This version maintains the strategy of targeting multiple operating systems, a tactic utilized since LockBit 2.0 was released in 2021.
The LockBit 5.0 variants are designed to target specific operating systems, using advanced techniques to evade detection and maximize impact.
The emergence of these variants in early September 2025 indicates a notable evolution.
Windows Variant: This version employs heavy obfuscation and packing, delivering its payload through DLL reflection to hinder analysis. It includes anti-analysis measures, such as patching the Event Tracing for Windows (ETW) API and terminating 63 security-related services. Additionally, it features a newly formatted help menu. Linux Variant: This version mirrors the Windows variant's functionality, providing consistent command-line options for targeting directories and file types. It logs activities, indicating encrypted files and excluded folders. ESXi Variant: Targeting VMware's ESXi infrastructure, this variant poses a critical threat as it can encrypt multiple virtual machines simultaneously. It includes parameters optimized for virtual machine encryption.
Trend Micro's analysis indicates that LockBit 5.0 is a direct evolution of LockBit 4.0, sharing identical hashing algorithms and API resolution methods, suggesting continuity in development.
Consistent behaviors are observed across the new variants. Encrypted files have a randomized 16-character extension, complicating identification and recovery. Additionally, the ransomware avoids execution on systems with Russian language settings or geolocated in Russia and clears event logs post-encryption.
The technical advancements in LockBit 5.0 enhance its threat level. Extensive obfuscation delays detection signature development, and the focus on virtualized environments increases its potential impact.
Organizations are advised to strengthen their security measures by proactively detecting threats and enhancing endpoint and network protections, with special emphasis on securing virtualization infrastructure.
Based on reporting by Cyber Security News.
