ZeroHour

lockbit5

ransomware group · aka LockBit 5.0, LockBit, LockBit 4.0, LockBit Black (LockBit 3.0 branding), Bitwise Spider (operator-side branding) · Russia (suspected); alleged leader 'LockBitSupp' identified as Russian national Dmitry Khoroshev per U.S. DOJ (2024) · active since Original LockBit first observed September 2019; 'LockBit 5.0' branding reported by vendors in 2025; exact 5.0 first-observed date unknown; this dashboard's leak-site tracking began 2026-09-04

Victims · 7d
5▼2
Victims · 30d
27active targets
Victims · 90d
53
All-time (tracked)
361since 2025-12-05
Last post
09-17 09:44UTC
Estimated earnings
Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…public reporting
Profile · glm-5.3-flash · updated

LockBit 5.0 is the latest version of the long-running LockBit ransomware-as-a-service brand, one of the most prolific RaaS operations observed since 2019. The operation uses an affiliate model and double extortion, publishing non-paying victims and stolen data on its leak site, consistent with the victim cadence tracked here. In February 2024, international law enforcement (Operation Cronos, FBI/NCA and partners) seized servers and disrupted the group, and the U.S. DOJ subsequently identified alleged leader LockBitSupp as Russian national Dmitry Khoroshev. LockBit continued operating after the disruption, with vendor reporting through 2025 describing ongoing victim postings; technical details unique to the 5.0 encryptor are not well documented publicly. Well-documented tradecraft includes VPN and edge-device exploitation for initial access, the custom StealBit exfiltration tool, and pressure tactics such as countdown timers on its leak site.

Tactics & tooling
  • Double extortion: file encryption plus data exfiltration with leak-site publication
  • Ransomware-as-a-service affiliate model with recruited access brokers
  • Initial access via exploited VPN and edge devices, and stolen credentials (per CISA/FBI #StopRansomware advisories)
  • Exploitation of known vulnerabilities, including FortiOS, Zerologon, PrintNightmare, Follina, and Citrix Bleed
  • Custom StealBit exfiltration tool; loader-based delivery (e.g., QakBot) observed in affiliate intrusions per vendor reporting
  • Intermittent encryption for speed; disables security software, deletes shadow copies, reboots into safe mode (per CISA/FBI advisories)
  • Leak-site pressure tactics: countdown timers, victim shaming, reposting of non-payers
Targeted sectors
manufacturingprofessional and legal serviceshealthcareconstruction and engineeringfinancial servicestransport and logisticsIT and managed services
Notable public victims

Royal Mail Group (UK postal service; 2022-2023), Boeing (2023; intrusion linked to Citrix Bleed, CVE-2023-4966), ICBC Financial Services (2023), Continental AG (2022), Accenture (2021), TSMC (2023; via supplier Kinmax per public reporting), Bridgestone Americas (2022)

Estimated earnings

Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit… — Public reporting: U.S. DOJ/UK NCA joint announcement on Operation Cronos (February 2024); no verified public figure specific to version 5.0.

Leak-site victims

VictimDiscoveredDetails
hennessyfunds.com · Dec 5, 2025
ehlers-inc.com · Dec 5, 2025
graphiquedefrance.com · Dec 5, 2025
arc-com.com · Dec 5, 2025
intellioan.com · Dec 5, 2025
aqhch.com.cn · Dec 5, 2025
fepasa.com.ar · Dec 5, 2025
grupotersa.com.mx · Dec 5, 2025
bioclimaservice.it · Dec 5, 2025
berjaya-air.com · Dec 5, 2025
montaury.com.br · Dec 5, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .