LockBit strikes with new 5.0 version, targeting Windows, Linux and ESXI systems
Essential information
- Published
- 12/02/2026 15:08
- Modified
- 12/02/2026 21:53
- Tags
- 2026-02-12 defense evasion double-extortion encryption esxi infrastructure linux lockbit ransomware smokeloader virtualization windows
- Related entities
- 6 observables, 1 intrusion sets (apt), 33 others
Description
LockBit 5.0, the latest version of the notorious ransomware, has been released with support for Windows, Linux, and ESXi systems. This update brings improved defense evasion, faster encryption, and enhanced modularity. The Windows variant employs extensive anti-analysis techniques, while Linux and ESXi versions remain unpacked. All variants share a common encryption scheme using XChaCha20 and Curve25519. LockBit 5.0 demonstrates a focus on enterprise and infrastructure targets, including explicit support for Proxmox virtualization. The group's data leak site reveals a primary focus on the U.S. business sector, with victims spanning various industries. LockBit's infrastructure has shown connections to SmokeLoader, suggesting possible cooperation or infrastructure reuse among malware operators.