216.73.217.22

Detailed Analysis of LockBit 5.0

· Published 21/01/2026 10:03 · Modified 21/01/2026 23:18

Export JSON

Essential information

Published
21/01/2026 10:03
Modified
21/01/2026 23:18
Tags
2026-01-21 abcd ransomware affiliate program choungdong conti cyber attack double-extortion encryption evasion techniques lockbit lockbit green ransomware
Related entities
3 observables, 1 intrusion sets (apt), 2 techniques (mitre)

Description

, originating as in 2019, has evolved to version 5.0 in September 2025. After a period of inactivity, it resumed operations in December 2025 with a reduced affiliate sign-up fee. 5.0, nicknamed , consists of a Loader and component. The Loader decrypts and executes the payload in memory, while the uses ChaCha20 and Curve25519 for . This update significantly enhances and attack efficiency, introducing features like Mutex, Execution Delay, and Wiper. The group's history includes affiliation with the Maze cartel, independent operations, and continuous upgrades. Mitigation strategies involve monitoring process behavior, applying security patches, and preparing for swift responses using provided IoCs and MITRE ATT&CK techniques.

External references