LockBit 5.0 Ransomware Introduces Advanced Encryption and Maintains Global Dominance
LockBit 5.0 has emerged as the latest evolution of the notorious ransomware-as-a-service operation, introducing sophisticated encryption algorithms and advanced anti-analysis techniques that significantly complicate detection and recovery efforts for targeted organizations. The malware now employs a combination of ChaCha20-Poly1305 for file encryption and X25519 with BLAKE2b for secure key exchange, while also terminating Volume Shadow Copy Service processes to prevent system recovery. LockBit 5.0’s runtime flexibility allows it to operate even without specific parameters, and its use of advanced packing and obfuscation further hinders static analysis by security professionals.
Despite increased law enforcement pressure, LockBit has sustained its position as a dominant global ransomware threat, accounting for a substantial share of attacks worldwide. The group’s operations have impacted a wide range of sectors, including IT, electronics, law firms, and religious institutions, resulting in billions of dollars in ransom payments and recovery costs. LockBit continues to leverage its dark web platform to publicly list compromised organizations and stolen data, using these tactics to pressure victims into paying ransoms.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
LockBit 5.0 reported as sustaining global ransomware dominance
A follow-up report stated that LockBit 5.0 continued to operate as a dominant global ransomware threat, affecting organizations worldwide and underscoring the group's sustained activity.
LockBit 5.0 emerges with new encryption and anti-analysis features
By early January 2026, researchers reported the emergence of LockBit 5.0, a new version of the ransomware featuring advanced cryptography, anti-analysis tactics, and recovery-prevention measures such as disabling backups and shadow copies.
LockBit remains a leading ransomware threat in 2023
Reporting indicates LockBit was responsible for about 21% of global ransomware activity in 2023, showing the group's continued prominence despite shifts in the threat landscape.
LockBit dominates global ransomware activity in 2021-2022
LockBit accounted for more than 30% of global ransomware attacks between August 2021 and August 2022, establishing itself as one of the most active ransomware operations worldwide.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


