lockbit5
Known ransomware group ACTIVE Currently active
LockBit 5.0 ("ChuongDong") emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform payloads targeting Windows, Linux, and VMware ESXi with enhanced evasion capabilities and continuing the RaaS affiliate model of its predecessors.
1
Total Claims
1
Critical
—
Records Claimed
1
Industries Hit
Active span: Sep 9, 2026 – Sep 9, 2026 · 1 organizations targeted
Currently active
Actor Threat Profile
Activity Timeline
Peak: Sep 2026 (1)Sep 2026
LessMore
Sep 2026Top Targeted Industries
Healthcare 1
Tradecraft & Infrastructure
0
Documented tools
0 / 0
MITRE tactics / techniques
23
Known leak sites