Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationransomware-tooling-evolutiondefense-evasion-methoddata-exfiltration-method

LockBit 5.0 Ransomware Expands Cross-Platform Attacks on Windows, Linux, and VMware ESXi

Updated 3mo agoFirst seen Feb 16, 20262 sources

Acronis Threat Research Unit reported active campaigns using LockBit 5.0, a major update to the LockBit ransomware-as-a-service (RaaS) operation that broadens targeting across Windows, Linux, and VMware ESXi in coordinated intrusions. The variant continues double extortion (data theft plus encryption) and is positioned for enterprise impact by enabling attackers to hit endpoints, servers, and hypervisors—where a single ESXi compromise can disrupt many virtual machines at once. Reporting also notes the group’s claimed ability to operate against Proxmox virtualization environments, further expanding the potential attack surface in organizations adopting alternative hypervisors.

Technical analysis highlights stronger and more enterprise-focused builds, with the Windows payload using advanced defense-evasion and anti-analysis techniques such as packing/obfuscation, DLL unhooking, process hollowing, and ETW (Event Tracing for Windows) patching, alongside log-clearing to reduce forensic visibility. The Linux/ESXi builds are described as less reliant on packing but use extensive string encryption to hinder detection, while maintaining strong encryption routines and using randomized file extensions; Acronis-linked reporting also cites faster encryption and continuity with LockBit 4’s design. Victimology cited in coverage indicates a heavy focus on the U.S. business sector and a broad spread across industries (including manufacturing, healthcare, education, financial services, and government), with dozens of recent leak-site postings used to pressure victims and demonstrate ongoing operational tempo despite law-enforcement disruption efforts.

Share:
LockBit 5.0 Ransomware Expands Cross-Platform Attacks on Windows, Linux, and VMware ESXi
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 16, 20264mo ago

Acronis publishes technical analysis of LockBit 5.0

Acronis Threat Research Unit reported identifying LockBit 5.0 in active campaigns and detailed its enhanced defense evasion, anti-analysis, and faster encryption capabilities. The analysis also described its use of XChaCha20 and Curve25519, randomized file extensions, multi-threaded encryption, and infrastructure links involving an IP previously associated with SmokeLoader activity.

LockBit 5.0 begins cross-platform attacks on Windows, Linux, and ESXi

Active campaigns using LockBit 5.0 targeted Windows, Linux, and VMware ESXi systems, expanding the group's reach across endpoints, servers, and virtualized infrastructure. Reporting also said the malware was advertised as working on all versions of Proxmox.

Dec 1, 20257mo ago

LockBit leak site reaches 60 listed victims

Since December 2025, the LockBit leak site reportedly accumulated 60 victim entries, indicating sustained activity by the operation. The reported victimology was centered on U.S. businesses, especially private companies, with additional impact across manufacturing, healthcare, education, financial services, and government.

Sep 1, 202510mo ago

LockBit 5.0 introduced as a new ransomware version

LockBit 5.0 was introduced in September 2025 as a major new release of the LockBit ransomware family. The variant was positioned for enterprise-focused attacks and operated under the group's ransomware-as-a-service model.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Affected products
2 linked
WindowsVmware Esxi
Organizations
2 linked
AcronisTines
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.