Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors lockbit5

Description

LockBit 5.0 ("ChuongDong") emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform payloads targeting Windows, Linux, and VMware ESXi with enhanced evasion capabilities and continuing the RaaS affiliate model of its predecessors. Known victims: 246

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

LockBit5 (ChuongDong) is a medium-sophistication criminal threat actor specializing in ransomware attacks targeting diverse industries globally. The group reemerged in September 2025 after being disrupted by law enforcement, employing cross-platform payloads for Windows, Linux, and VMware ESXi with enhanced evasion techniques. Operating as part of the Ransomware-as-a-Service (RaaS) affiliate model, LockBit5 has demonstrated a high volume of activity, compromising over 246 victims across industries like healthcare, education, logistics, and government.

Goals & Targeting

LockBit5 demonstrates strategic objectives centered on generating financial profit through ransomware operations. The group systematically targets industries that are less likely to have robust cybersecurity measures in place, such as healthcare facilities, educational institutions, and small-to-medium enterprises (SMEs). This approach maximizes their return on investment while minimizing risk. The choice of cross-platform targeting reflects an understanding of the diverse IT environments organizations may operate within, allowing for broader attack vectors.

Enhanced Description

LockBit5, also referred to as ChuongDong, represents the latest iteration of the LockBit ransomware group following their takedown in February 2024. This resurgence marked a significant evolution, introducing cross-platform capabilities that target Windows, Linux, and VMware ESXi environments. The group employs a Ransomware-as-a-Service (RaaS) model, enabling affiliates to carry out attacks on behalf of the core operators. LockBit5's payloads are designed with enhanced evasion techniques, making them more challenging for traditional security measures to detect. Their operational strategy involves targeted campaigns against organizations across multiple regions and sectors, with a particular focus on extracting financial gains through ransom payments and data exfiltration.

Key Capabilities

  • Cross-platform payload delivery
  • Enhanced evasion techniques
  • Ransomware-as-a-Service (RaaS) model
  • Targeted phishing and social engineering campaigns
  • Data exfiltration and encryption

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1566.002
T1078
T1547
T1603
T1568.002
T1572
T1555
T1083
T1087
T1548.001
T1005
T1048
T1069

Software / Tooling

Cobalt Strike
Mimi Katz
Custom malware/compile tools DLLs
Ransomware Orchestration-as-a-Service (RaaS)

Suggested Tags

APT29
Ransomware-as-a-Service
Financial Profit Motive
Healthcare Sector Targeting
Education Sector Targeting
Critical Infrastructure Targeting

Confidence Assessment

moderate, While LockBit5's operations are well-documented due to their high victim count and sample IOCs, gaps exist in understanding their exact TTPs beyond observed patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

177

Campaigns

13

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT29
Ransomware-as-a-Service
Financial Profit Motive
Healthcare Sector Targeting
Education Sector Targeting
Critical Infrastructure Targeting

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 17, 2023
Last Seen
Aug 4, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.