Cyber Security News

New LockBit 5.0 Ransomware Variant Attacking Windows, Linux, and ESXi Systems

Following a major law enforcement disruption in February 2024, the notorious LockBit ransomware group has resurfaced, marking its sixth anniversary with the release of a new version: LockBit 5.0.

Trend Micro has identified and analyzed binaries for Windows, Linux, and VMware ESXi, confirming the group’s continued focus on cross-platform attacks that can cripple entire enterprise networks.

The discovery of these new variants in early September 2025 signals a significant evolution of the ransomware. This latest version continues the group’s strategy of targeting multiple operating systems simultaneously, a tactic seen since LockBit 2.0 was released in 2021.

Advanced Cross-Platform Attacks

The LockBit 5.0 variants are created for their target operating systems, employing sophisticated techniques to evade detection and maximize damage.

  • Windows Variant: This version uses heavy obfuscation and packing, loading its malicious payload through DLL reflection to complicate analysis. It also implements anti-analysis measures, such as patching the Event Tracing for Windows (ETW) API and terminating 63 different security-related services. The Windows variant also features a newly formatted and more user-friendly help menu.
Windows variant
  • Linux Variant: The Linux version mirrors the functionality of its Windows counterpart, providing attackers with a consistent set of command-line options to target specific directories and file types. It can log its activities, showing which files are being encrypted and which folders are excluded.
Linux variant
  • ESXi Variant: A dedicated variant specifically targets VMware’s ESXi virtualization infrastructure. This represents a critical threat, as compromising a single ESXi host can allow attackers to encrypt dozens or even hundreds of virtual machines at once, causing massive disruption. The ESXi variant includes parameters optimized for virtual machine encryption.
ESXi variant

Trend Micro analysis shows that LockBit 5.0 is a direct evolution of its predecessor, LockBit 4.0. Both versions share identical hashing algorithms and methods for API resolution, indicating the same developers have built upon their existing codebase.

Key behaviors are consistent across the new variants. Encrypted files are appended with a randomized 16-character extension, making identification and recovery more difficult.

The ransomware also includes checks to avoid executing on systems with Russian language settings or geolocated in Russia. After the encryption process is complete, it clears event logs to cover its tracks.

The technical improvements in LockBit 5.0 make it significantly more dangerous than previous versions. The heavy obfuscation delays the development of detection signatures, while the focus on virtualized environments amplifies its potential impact.

The group’s ability to regroup and release an upgraded ransomware after Operation Cronos demonstrates its resilience.

Organizations are advised to enhance their security posture by proactively hunting for threats and reinforcing endpoint and network protections. Special attention should be given to securing virtualization infrastructure, as it has become a primary target.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago