ZeroHour

lockbit5

ransomware group · aka LockBit 5.0, LockBit, LockBit 4.0, LockBit Black (LockBit 3.0 branding), Bitwise Spider (operator-side branding) · Russia (suspected); alleged leader 'LockBitSupp' identified as Russian national Dmitry Khoroshev per U.S. DOJ (2024) · active since Original LockBit first observed September 2019; 'LockBit 5.0' branding reported by vendors in 2025; exact 5.0 first-observed date unknown; this dashboard's leak-site tracking began 2026-09-04

Victims · 7d
5▼1
Victims · 30d
26active targets
Victims · 90d
52
All-time (tracked)
360since 2025-12-05
Last post
09-14 18:42UTC
Estimated earnings
Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…public reporting
Profile · glm-5.3-flash · updated

LockBit 5.0 is the latest version of the long-running LockBit ransomware-as-a-service brand, one of the most prolific RaaS operations observed since 2019. The operation uses an affiliate model and double extortion, publishing non-paying victims and stolen data on its leak site, consistent with the victim cadence tracked here. In February 2024, international law enforcement (Operation Cronos, FBI/NCA and partners) seized servers and disrupted the group, and the U.S. DOJ subsequently identified alleged leader LockBitSupp as Russian national Dmitry Khoroshev. LockBit continued operating after the disruption, with vendor reporting through 2025 describing ongoing victim postings; technical details unique to the 5.0 encryptor are not well documented publicly. Well-documented tradecraft includes VPN and edge-device exploitation for initial access, the custom StealBit exfiltration tool, and pressure tactics such as countdown timers on its leak site.

Tactics & tooling
  • Double extortion: file encryption plus data exfiltration with leak-site publication
  • Ransomware-as-a-service affiliate model with recruited access brokers
  • Initial access via exploited VPN and edge devices, and stolen credentials (per CISA/FBI #StopRansomware advisories)
  • Exploitation of known vulnerabilities, including FortiOS, Zerologon, PrintNightmare, Follina, and Citrix Bleed
  • Custom StealBit exfiltration tool; loader-based delivery (e.g., QakBot) observed in affiliate intrusions per vendor reporting
  • Intermittent encryption for speed; disables security software, deletes shadow copies, reboots into safe mode (per CISA/FBI advisories)
  • Leak-site pressure tactics: countdown timers, victim shaming, reposting of non-payers
Targeted sectors
manufacturingprofessional and legal serviceshealthcareconstruction and engineeringfinancial servicestransport and logisticsIT and managed services
Notable public victims

Royal Mail Group (UK postal service; 2022-2023), Boeing (2023; intrusion linked to Citrix Bleed, CVE-2023-4966), ICBC Financial Services (2023), Continental AG (2022), Accenture (2021), TSMC (2023; via supplier Kinmax per public reporting), Bridgestone Americas (2022)

Estimated earnings

Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit… — Public reporting: U.S. DOJ/UK NCA joint announcement on Operation Cronos (February 2024); no verified public figure specific to version 5.0.

Leak-site victims

VictimDiscoveredDetails
uniplaclages.edu.br · Dec 30, 2025
drako.com.mx · Dec 30, 2025
inspired.ee · Dec 30, 2025
zszeleznice.cz · Dec 30, 2025
surfishtrade.com · Dec 30, 2025
towellholding.com · Dec 30, 2025
tecnicarobertorocca.edu.ar · Dec 30, 2025
technicare.com.br · Dec 30, 2025
tealca.com · Dec 30, 2025
soeuae.ae · Dec 30, 2025
savantivibranti.com · Dec 30, 2025
puzio-saunierduval.fr · Dec 30, 2025
optral.com · Dec 30, 2025
omf.org · Dec 30, 2025
occgrouptr.com · Dec 30, 2025
mostykatowice.pl · Dec 30, 2025
prommgroup.com · Dec 30, 2025
q-ads.com · Dec 30, 2025
smed.at · Dec 30, 2025
clipan.co.id · Dec 30, 2025
mc2engineers.com · Dec 30, 2025
lfval.net · Dec 30, 2025
laval-virtual.com · Dec 30, 2025
kraslice.cz · Dec 30, 2025
jefar.be · Dec 30, 2025
gumustasmaden.com.tr · Dec 30, 2025
geselektrik.com.tr · Dec 30, 2025
gccservices.eu · Dec 30, 2025
fresh2you.eu · Dec 30, 2025
fortrex.hu · Dec 30, 2025
emresorts.com · Dec 30, 2025
d-klima.cz · Dec 30, 2025
csd-drancy.com · Dec 30, 2025
cmc.com.br · Dec 30, 2025
casabotas.es · Dec 30, 2025
carseo.de · Dec 30, 2025
bwk-berlin.de · Dec 30, 2025
bonfilet.com.tr · Dec 30, 2025
behranlift.com · Dec 30, 2025
arabfalcons.com · Dec 30, 2025
anwalt-austria.at · Dec 30, 2025
amw-treuhand.ch · Dec 30, 2025
agfri.com · Dec 30, 2025
acarlar.com.tr · Dec 30, 2025
rdmetals.nl · Dec 30, 2025
ambisig.com · Dec 30, 2025
shwapno.com · Dec 30, 2025
semplastik.com.tr · Dec 30, 2025
proplastics.co.zw · Dec 30, 2025
platinumpws.com · Dec 30, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .