LockBit 5.0 ("ChuongDong") emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform payloads targeting Windows, Linux, and VMware ESXi with enhanced evasion capabilities and continuing the RaaS affiliate model of its predecessors. Known victims: 246
Objectives
Executive Summary
LockBit5 (ChuongDong) is a medium-sophistication criminal threat actor specializing in ransomware attacks targeting diverse industries globally. The group reemerged in September 2025 after being disrupted by law enforcement, employing cross-platform payloads for Windows, Linux, and VMware ESXi with enhanced evasion techniques. Operating as part of the Ransomware-as-a-Service (RaaS) affiliate model, LockBit5 has demonstrated a high volume of activity, compromising over 246 victims across industries like healthcare, education, logistics, and government.
Goals & Targeting
LockBit5 demonstrates strategic objectives centered on generating financial profit through ransomware operations. The group systematically targets industries that are less likely to have robust cybersecurity measures in place, such as healthcare facilities, educational institutions, and small-to-medium enterprises (SMEs). This approach maximizes their return on investment while minimizing risk. The choice of cross-platform targeting reflects an understanding of the diverse IT environments organizations may operate within, allowing for broader attack vectors.
Enhanced Description
LockBit5, also referred to as ChuongDong, represents the latest iteration of the LockBit ransomware group following their takedown in February 2024. This resurgence marked a significant evolution, introducing cross-platform capabilities that target Windows, Linux, and VMware ESXi environments. The group employs a Ransomware-as-a-Service (RaaS) model, enabling affiliates to carry out attacks on behalf of the core operators. LockBit5's payloads are designed with enhanced evasion techniques, making them more challenging for traditional security measures to detect. Their operational strategy involves targeted campaigns against organizations across multiple regions and sectors, with a particular focus on extracting financial gains through ransom payments and data exfiltration.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Suggested Tags
Confidence Assessment
moderate, While LockBit5's operations are well-documented due to their high victim count and sample IOCs, gaps exist in understanding their exact TTPs beyond observed patterns.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
177
Campaigns
13
IOCs
0
Observed Data
0
Tactics