A dangerous new version of the LockBit ransomware has begun to spread, causing concern among organizations and businesses around the world. LockBit 5.0, released in September 2025, marks a significant upgrade to the ransomware family that has wreaked havoc in recent years, incorporating advanced encryption techniques and detection evasion mechanisms.

Broad targeting and double blackmail
LockBit 5.0 now targets Windows, Linux, and ESXi, meaning it is capable of affecting a variety of infrastructure environments. It operates as ransomware-as-a-service and uses model dual-extortion, encrypting files while simultaneously stealing data in order to pressure victims into paying a ransom. The primary target remains the U.S. business sector, with private companies accounting for approximately 67% of recorded victims. Additionally, industries such as manufacturing, healthcare, education, financial services, and government services are also affected.
See also: Microsoft: ClickFix Attack Using DNS and Nslookup
Since December 2025, LockBit's data leak site has recorded 60 victim listings , demonstrating the widespread distribution and aggressiveness of the new variant. Particularly concerning is its ability to target Proxmox , a popular open-source virtualization platform increasingly used by enterprises.
Advanced techniques and high-level encryption
Acronis analysts point out that LockBit 5.0 has advanced defense evasion capabilities and achieves faster encryption compared to its predecessor. The Windows version integrates DLL unhooking, process hollowing, and Event Tracing mechanisms for Windows patching , while cleaning all system logs to eliminate traces.

Linux and ESXi versions encrypt almost all of their strings to avoid detection. All platforms use a common encryption scheme XChaCha20 for symmetric and Curve25519 for asymmetric encryption, while each file is given a random 16-character extension to make it harder to identify. Creating multiple encryption threads based on the number of processors ensures speed and efficiency.
See also: Pastebin comments promote ClickFix JavaScript attack
Avoidance mechanisms and geographical controls
LockBit 5.0 implements sophisticated evasion tactics, such as Mixed Boolean-Arithmetic obfuscation and performs geolocation checks to avoid systems in post-Soviet countries. Before encryption, it checks the system language to avoid Russian-speaking environments. The ransomware executes via the legitimate defrag.exe utility , and after encryption is complete, it disables Event Tracing and clears logs using the EvtClearLog function .
Infrastructure analysis reveals that the LockBit leak site is hosted on an IP associated with SmokeLoader, indicating possible collaboration between cybercriminal groups.

Recommended protection practices
Organizations looking to protect themselves from LockBit 5.0 should implement multi-layered security controls, including regular offline backups, network segmentation, endpoint detection and response solutions , and regular patching. Employee training on phishing remains critical, while administrators should monitor suspicious process activity, unusual file encryption , and attempts to disable security logging mechanisms.
See also: Zero Trust: hype or real defense?
The new LockBit 5.0 release is a clear reminder that organizations must strengthen their security systems and adopt preventive practices to address the ever-evolving threats of cyberspace.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
