{"id":7956,"date":"2025-10-26T10:03:37","date_gmt":"2025-10-26T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/26\/lockbit-5-0-actively-attacking-windows-linux-and-esxi-environments\/"},"modified":"2025-10-26T10:03:37","modified_gmt":"2025-10-26T10:03:37","slug":"lockbit-5-0-actively-attacking-windows-linux-and-esxi-environments","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/26\/lockbit-5-0-actively-attacking-windows-linux-and-esxi-environments\/","title":{"rendered":"LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments"},"content":{"rendered":"<p>    LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The notorious LockBit ransomware operation has resurfaced with a vengeance after months of dormancy following Operation Cronos takedown efforts in early 2024.<\/p>\n<p>Despite law enforcement disruptions and infrastructure seizures, the group\u2019s administrator, LockBitSupp, has successfully rebuilt the operation and launched LockBit 5.0, internally codenamed \u201cChuongDong.\u201d<\/p>\n<p>This latest variant represents a significant evolution in the group\u2019s <a href=\"https:\/\/cybersecuritynews.com\/everest-ransomware-gang-leak-site-hacked\/\">ransomware<\/a> capabilities, targeting organizations across multiple platforms with enhanced technical sophistication.<\/p>\n<p>Throughout September 2025, the revived operation demonstrated its operational recovery by compromising a dozen organizations across Western Europe, the Americas, and Asia.<\/p>\n<p>Half of these incidents involved the newly released LockBit 5.0 variant, while the remainder utilized LockBit Black.<\/p>\n<p>The attacks primarily focused on Windows environments, accounting for approximately 80% of infections, with ESXi and Linux systems comprising the remaining 20%.<\/p>\n<p>Check Point analysts <a href=\"https:\/\/blog.checkpoint.com\/research\/lockbit-returns-and-it-already-has-victims\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> these campaigns as clear evidence that LockBit\u2019s Ransomware-as-a-Service model has successfully reactivated its affiliate network.<\/p>\n<p>The rapid return highlights the resilience of established cybercriminal enterprises.<\/p>\n<p>After announcing its comeback on underground forums in early September, LockBitSupp recruited new affiliates by requiring roughly $500 in Bitcoin deposits for access to the control panel and <a href=\"https:\/\/cybersecuritynews.com\/nist-finalised-3-encryption-tools-for-quantum-cyberattacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">encryption tools<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-enhanced-encryption-and-evasion-capabilities\"><strong>Enhanced Encryption and Evasion Capabilities<\/strong><\/h2>\n<p>LockBit 5.0 introduces several technical improvements designed to maximize impact while minimizing detection.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhA1g63QVfZ8OgkD_moNMlOzQNoYCbj_qtnmDi44KRWte-pmjG8jjH7GE1HYVWRr2qABdGF6nTT_SrJ_j62RQkF4mNCB9MSm-CuQOQKtTjTi3VaX4T2ry_3mibjWdB3-jtiwbXBxqDDoyxXoFcvo7ppH-IKHSC5a4z28PuCvnw2i7j4ED9v0EGWZZY5Ik8\/s16000\/LockBit%25205.0%2520affiliate%2520registration%2520screen%2520%28Source%2520-%2520Check%2520Point%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">LockBit 5.0 affiliate registration screen (Source \u2013 Check Point)<\/figcaption><\/figure>\n<\/div>\n<p>The malware now supports multi-platform deployments with dedicated builds for Windows, Linux, and ESXi environments.<\/p>\n<p>Its encryption routines have been optimized to reduce the response window available to defenders, enabling faster system-wide file encryption.<\/p>\n<p>The variant employs randomized 16-character file extensions to evade signature-based detection mechanisms.<\/p>\n<p>Enhanced anti-analysis features obstruct <a href=\"https:\/\/cybersecuritynews.com\/forensic-timeliner-windows-forensic-tool\/\" target=\"_blank\" rel=\"noreferrer noopener\">forensic<\/a> investigation and reverse engineering attempts, making it significantly more challenging for security researchers to analyze the malware\u2019s behavior.<\/p>\n<p>Updated ransom notes identify themselves as <a href=\"https:\/\/cybersecuritynews.com\/20-cves-exploited-by-lockbit-uncovered\/\" target=\"_blank\" rel=\"noreferrer noopener\">LockBit<\/a> 5.0 and provide personalized negotiation links with a 30-day deadline before stolen data publication.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/lockbit-5-0-actively-attacking\/\">LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/lockbit-5-0-actively-attacking\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments The notorious LockBit ransomware operation has resurfaced with a vengeance after months of dormancy following Operation Cronos takedown efforts in early 2024. Despite law enforcement disruptions and infrastructure seizures, the group\u2019s administrator, LockBitSupp, has successfully rebuilt the operation and launched LockBit 5.0, internally codenamed \u201cChuongDong.\u201d This [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7956","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7956"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7956"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7956\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}