lockbit5
LockBit 5.0 ("ChuongDong") emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform payloads targeting Windows, Linux, and VMware ESXi with enhanced evasion capabilities and continuing the RaaS affiliate model of its predecessors.
observed victims (by country)
United StatesNetherlandsGermanyFrance
observed sectors
ManufacturingProfessional ServicesTechnologyOther
29 victims · last active 31 Aug 2026
recent activity · our intel
source: ransomware.live1 refs →