Researchers report that LockBit has resumed operations with a new LockBit 5.0 strain that targets Windows, Linux, and VMware ESXi systems, extending the group’s established cross-platform ransomware model after the disruption caused by Operation Cronos. Analysis of a newly discovered sample found strong code continuity with LockBit 4.0, indicating the malware is an evolution of the original codebase rather than a copycat. The new version adds heavy obfuscation, anti-analysis, and anti-forensics capabilities, including in-memory payload loading through DLL reflection, ETW patching, security service termination, and event log clearing, while the ESXi variant is built to encrypt virtualized environments at scale.
Separate reporting ties LockBit activity to real-world intrusions and common access vectors. SecurityScorecard assessed a claimed attack on a major state-owned Southeast Asian bank and found network and malware evidence consistent with credential theft, SSH/RDP-based access, and possible data exfiltration before and after the victim appeared on LockBit’s leak site, though some public claims could not be independently verified. Another SecurityScorecard investigation found attackers exploiting PaperCut flaws CVE-2023-27350 and CVE-2023-27351, with CVE-2023-27350 used to deliver LockBit in observed cases, underscoring how the group and its affiliates continue to pair opportunistic vulnerability exploitation with mature, multi-platform ransomware tooling.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
LockBit publicly claimed an attack against a major state-owned bank in Southeast Asia on May 8. SecurityScorecard later analyzed network and malware evidence consistent with multiple stages of a ransomware intrusion.
A reverse-engineering writeup focused on LockBit ransomware v4.0 was published on March 15, 2025.
Operation Cronos disrupted LockBit group infrastructure in February 2024, according to Trend Research.
Security researchers announced the discovery of CVE-2023-27350 and CVE-2023-27351 on April 26, 2023. CVE-2023-27350 was identified as the more severe flaw, enabling remote code execution.
A PaperCut customer detected suspicious behavior on a PaperCut server on April 18, 2023, bringing the vulnerabilities to the company’s attention.
PaperCut concluded that the earliest activity suggesting possible exploitation of CVE-2023-27350 and CVE-2023-27351 appeared on April 14, 2023.
Trend Research identified and analyzed a new LockBit 5.0 ransomware binary found in the wild and confirmed Windows, Linux, and ESXi variants. The researchers concluded it is an evolution of the original LockBit codebase rather than an imitation or rebrand.
Trend Research reported that the LockBit group resurfaced in early September and announced the release of LockBit 5.0 for its sixth anniversary.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 65 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcesecurityscorecard.com
Open sourcesecurityscorecard.com
Open sourcechuongdong.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.