HomeSecurityNew LockBit 5.0 ransomware targets Windows, Linux and ESXi

New LockBit 5.0 ransomware targets Windows, Linux, and ESXi

Following a major law enforcement operation, in February 2024, the notorious LockBit ransomware resurfaced, celebrating its sixth anniversary with the release of a new version: LockBit 5.0.

LockBit 5.0 ransomware

Trend Micro has identified and analyzed binaries for Windows, Linux, and VMware ESXi, confirming the team's continued focus on cross-platform attacks that can cripple entire corporate networks.

The discovery of these new variants in early September 2025 marks a significant evolution of the ransomware. This latest version continues the group's strategy of targeting multiple operating systems simultaneously, a tactic seen since the release of LockBit 2.0 in 2021.

See also: COLDRIVER group distributes new backdoor BAITSWITCH

LockBit 5.0: Variants for Windows, Linux and VMware ESXi

LockBit 5.0 variants are tailored to target operating systems, using sophisticated techniques to evade detection and maximize damage.

  • Windows variant: This version uses heavy obfuscation and packing, loading its malicious payload via DLL reflection to make analysis more difficult. It also implements anti-analysis measures, such as patching the Event Tracing for Windows (ETW) API and stopping 63 different security-related services. The Windows variant also features a newly formatted and more user-friendly help menu.
  • Linux Variant: The Linux version mirrors the functionality of the Windows version, providing attackers with a consistent set of command-line options to target specific directories and file types. It can log its activities, showing which files are encrypted and which folders are excluded.
  • ESXi Variant: A variant specifically targeting VMware ESXi virtualization infrastructure. This represents a critical threat, as compromising a single ESXi host could allow attackers to encrypt dozens or even hundreds of virtual machines at once, causing massive disruption. The ESXi variant includes parameters optimized for virtual machine encryption.

See also: Volvo Group: Data breach following Ransomware attack

New LockBit 5.0 ransomware targets Windows, Linux, and ESXi

Trend Micro's analysis shows that LockBit 5.0 is a direct evolution of its predecessor, LockBit 4.0. Both versions share identical hashing algorithms and API resolution methods , indicating that the same developers have built on their existing code.

The basic behaviors are consistent across all new variants. A random 16-character extension is added to encrypted files , making identification and recovery more difficult.

The ransomware also includes checks to avoid execution on systems with Russian language settings (or located in Russia). After the encryption process is complete, it deletes logs to cover its tracks.

Technical improvements in LockBit 5.0 make it significantly more dangerous than previous versions. Heavy obfuscation delays the development of detection signatures, while the focus on virtual environments amplifies its potential impact.

The group's ability to regroup and release an upgraded ransomware after Operation Cronos demonstrates its resilience.

Organizations are urged to strengthen their security posture, proactively searching for threats and strengthening endpoint and network protections.

See also: Android banking trojans mimic government apps

New LockBit 5.0 ransomware targets Windows, Linux, and ESXi

Ransomware protection

  • Stay up to date on the latest ransomware trends and tactics used by attackers
  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to your network
  • Keep sensitive data encrypted
  • Update all your devices and systems with the latest security patches
  • Conduct regular security audits and penetration testing
  • Use strong, unique passwords and change them regularly.
  • Limit user access to only necessary systems and information
  • Consider using  email security solutions for additional protection against phishing attacks
  • Have a recovery plan to quickly restore systems in the event of an attack
  • Enable the display of file extensions
  • Invest in advanced protection solutions
  • Use sandboxing for email attachments
  • Keep backup copies of your data
Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS