ZeroHour

lockbit5

ransomware group · aka LockBit 5.0, LockBit, LockBit 4.0, LockBit Black (LockBit 3.0 branding), Bitwise Spider (operator-side branding) · Russia (suspected); alleged leader 'LockBitSupp' identified as Russian national Dmitry Khoroshev per U.S. DOJ (2024) · active since Original LockBit first observed September 2019; 'LockBit 5.0' branding reported by vendors in 2025; exact 5.0 first-observed date unknown; this dashboard's leak-site tracking began 2026-09-04

Victims · 7d
5▼2
Victims · 30d
27active targets
Victims · 90d
53
All-time (tracked)
361since 2025-12-05
Last post
09-17 09:44UTC
Estimated earnings
Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…public reporting
Profile · glm-5.3-flash · updated

LockBit 5.0 is the latest version of the long-running LockBit ransomware-as-a-service brand, one of the most prolific RaaS operations observed since 2019. The operation uses an affiliate model and double extortion, publishing non-paying victims and stolen data on its leak site, consistent with the victim cadence tracked here. In February 2024, international law enforcement (Operation Cronos, FBI/NCA and partners) seized servers and disrupted the group, and the U.S. DOJ subsequently identified alleged leader LockBitSupp as Russian national Dmitry Khoroshev. LockBit continued operating after the disruption, with vendor reporting through 2025 describing ongoing victim postings; technical details unique to the 5.0 encryptor are not well documented publicly. Well-documented tradecraft includes VPN and edge-device exploitation for initial access, the custom StealBit exfiltration tool, and pressure tactics such as countdown timers on its leak site.

Tactics & tooling
  • Double extortion: file encryption plus data exfiltration with leak-site publication
  • Ransomware-as-a-service affiliate model with recruited access brokers
  • Initial access via exploited VPN and edge devices, and stolen credentials (per CISA/FBI #StopRansomware advisories)
  • Exploitation of known vulnerabilities, including FortiOS, Zerologon, PrintNightmare, Follina, and Citrix Bleed
  • Custom StealBit exfiltration tool; loader-based delivery (e.g., QakBot) observed in affiliate intrusions per vendor reporting
  • Intermittent encryption for speed; disables security software, deletes shadow copies, reboots into safe mode (per CISA/FBI advisories)
  • Leak-site pressure tactics: countdown timers, victim shaming, reposting of non-payers
Targeted sectors
manufacturingprofessional and legal serviceshealthcareconstruction and engineeringfinancial servicestransport and logisticsIT and managed services
Notable public victims

Royal Mail Group (UK postal service; 2022-2023), Boeing (2023; intrusion linked to Citrix Bleed, CVE-2023-4966), ICBC Financial Services (2023), Continental AG (2022), Accenture (2021), TSMC (2023; via supplier Kinmax per public reporting), Bridgestone Americas (2022)

Estimated earnings

Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit… — Public reporting: U.S. DOJ/UK NCA joint announcement on Operation Cronos (February 2024); no verified public figure specific to version 5.0.

Leak-site victims

VictimDiscoveredDetails
platinumpws.com · Dec 30, 2025
npiav.com · Dec 30, 2025
manuaco.pt · Dec 30, 2025
itgsolutions.com · Dec 30, 2025
grupoconstrutodo.com · Dec 30, 2025
klax.de · Dec 30, 2025
labayenylaborde.com · Dec 30, 2025
samkee.com · Dec 30, 2025
collinscomputing.com · Dec 30, 2025
drogales.com.br · Dec 30, 2025
eroselevators.com · Dec 30, 2025
esopdirect.com · Dec 30, 2025
fortishealthcare.com · Dec 30, 2025
keystoliteracy.com · Dec 19, 2025
pdcm.com · Dec 19, 2025
tuscon-physicans.com · Dec 19, 2025
clarindahealth.com · Dec 19, 2025
maasa.com.ar · Dec 19, 2025
axxel.biz · Dec 19, 2025
firstrateak.com · Dec 19, 2025
jvdbassoc.com · Dec 19, 2025
walters-group.co.uk · Dec 19, 2025
milanoristorazione.it · Dec 7, 2025
kap.co.th · Dec 7, 2025
cadopt.com · Dec 7, 2025
marriott.com · Dec 7, 2025
four-points.marriott.com · Dec 7, 2025
iscot.it · Dec 7, 2025
tracsa.com.mx · Dec 7, 2025
chmsbc.org.br · Dec 7, 2025
elundini.gov.za · Dec 7, 2025
comune.balmuccia.vc.it · Dec 7, 2025
felixvet.com · Dec 7, 2025
pilgrimpackaging.com · Dec 7, 2025
physiciansmedicalbilling.net · Dec 7, 2025
ende.bo · Dec 7, 2025
aeamg.org.br · Dec 7, 2025
incolease.com · Dec 7, 2025
insightchicago.com · Dec 5, 2025
jobberswarehouse.com · Dec 5, 2025
rjwalker.com · Dec 5, 2025
topackt.com · Dec 5, 2025
aerworldwide.com · Dec 5, 2025
51talk.com · Dec 5, 2025
terracaribbean.com · Dec 5, 2025
brumfieldconstructioninc.com · Dec 5, 2025
asiapacificex.com · Dec 5, 2025
crystal-d.com · Dec 5, 2025
visionproducts.llc · Dec 5, 2025
kll-law.com · Dec 5, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .