216.73.216.6

New LockBit 5.0 Targets Windows, Linux, ESXi

· Published 29/09/2025 08:13 · Modified 29/09/2025 08:53

Export JSON

Essential information

Published
29/09/2025 08:13
Modified
29/09/2025 08:53
Tags
2025-09-29 anti-analysis cross-platform dll reflection encryption esxi lockbit 5.0 obfuscation ransomware virtualization
Related entities
5 observables, 1 intrusion sets (apt), 9 techniques (mitre), 1 malware, 1 others

Description

Trend Research analyzed the latest version of LockBit , , which exhibits advanced , techniques, and capabilities for Windows, Linux, and systems. The Windows variant uses heavy and packing, loading its payload through and implementing techniques. The Linux variant has similar functionality with command-line options for targeting specific directories and file types. The variant specifically targets VMware infrastructure. All variants use randomized 16-character file extensions, have Russian language system avoidance, and clear event logs post-. The existence of multiple variants confirms LockBit's continued strategy, enabling simultaneous attacks across entire enterprise networks including virtualized environments.

External references