LO

lockbit5

Known ransomware group ACTIVE
Currently active

LockBit 5.0 ("ChuongDong") emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform payloads targeting Windows, Linux, and VMware ESXi with enhanced evasion capabilities and continuing the RaaS affiliate model of its predecessors.

1

Total Claims

1

Critical

Records Claimed

1

Industries Hit

Active span: Sep 9, 2026 – Sep 9, 2026 · 1 organizations targeted

Currently active
Activity 1.9 Severity 10.0 Sectors 2.3 Tooling 0.0

Actor Threat Profile

Activity Timeline

Peak: Sep 2026 (1)
Sep 2026
LessMore
Sep 2026

Share this profile

Shareable intel card for lockbit5

Top Targeted Industries

Healthcare 1

Tradecraft & Infrastructure

0

Documented tools

0 / 0

MITRE tactics / techniques

23

Known leak sites

Full intelligence profile on ransomware.live →

Targeted Organizations

Claims by lockbit5

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.