LockBit is back. After the 2024 Operation Cronos takedown gutted its infrastructure, the group relaunched as LockBit 5.0 in September 2025 and, by June 2026, had climbed to roughly 7% of tracked ransomware attacks, up from about 1% in May. The new build is multi-platform, faster, and hardened against analysis, with randomized file extensions and a revamped affiliate program. On a single day in mid-July 2026 the operation claimed nine victims, concentrated in hospitality. LockBit’s return is the clearest test yet of whether a disrupted brand can rebuild trust with affiliates.
Who is LockBit?
LockBit is a ransomware-as-a-service operation first seen in 2019 that became the world’s most prolific ransomware brand before law enforcement disrupted it in February 2024 under Operation Cronos. We covered that disruption and its aftermath in LockBit, two years after Operation Cronos. The 5.0 relaunch is the group’s attempt to reclaim the position it lost, and its June 2026 numbers show the effort gaining traction. Track new listings on the Ransomtracker feed.
How big is the resurgence?
The June 2026 data is the headline. Check Point tracking put LockBit at around 7% of attacks that month, a sharp jump from roughly 1% in May, and daily leak-site monitoring recorded LockBit 5.0 claiming nine victims on a single day in mid-July, largely in the hospitality sector. That trajectory does not restore LockBit to its pre-Cronos dominance, but it reverses the post-takedown decline and signals that affiliates are returning to a brand many had written off.
What is new in LockBit 5.0?
The 5.0 build is a technical refresh aimed at reliability and evasion. It ships as a multi-platform toolkit, roughly 80% of observed builds targeting Windows and about 20% ESXi or Linux, with enhanced anti-analysis features, randomized 16-character file extensions, and faster encryption. The affiliate program was rebuilt with individualized panels and a $500 Bitcoin deposit to join, a structure designed to rebuild an operator base that scattered after Cronos. The randomized extensions complicate signature-based detection and victim triage alike.
Can a disrupted brand really come back?
That is the open question LockBit 5.0 is answering in real time. Law-enforcement takedowns are meant to destroy trust as much as infrastructure: affiliates fear that a compromised brand is a honeypot. LockBit’s June surge suggests some operators have decided the money outweighs the risk. Whether that holds depends on whether the group can avoid a second disruption and keep paying affiliates reliably. For defenders, the lesson is that a takedown buys time, not permanence, and detection has to keep pace with a rebranded, retooled version of a familiar threat.
How to defend against LockBit 5.0
The fundamentals hold. Close the common entry points, exposed remote access, unpatched edge devices, and phishable credentials, and enforce phishing-resistant multi-factor authentication. Protect ESXi and Linux hosts, since a fifth of LockBit 5.0 builds target them. Keep offline, tested backups so encryption is recoverable, and treat any nine-in-a-day surge in leak-site listings as a signal to review exposure in the sectors being hit. Endpoint controls that catch the pre-encryption phase are covered in our business ransomware protection guide.
Frequently asked questions
Is LockBit still active in 2026?
Yes. LockBit relaunched as version 5.0 in September 2025 and grew to roughly 7% of tracked attacks by June 2026, reversing its post-takedown decline.
What happened to LockBit in Operation Cronos?
In February 2024, a law-enforcement coalition disrupted LockBit’s infrastructure under Operation Cronos, seizing servers and damaging the brand. LockBit 5.0 is the group’s attempt to rebuild.
What is different about LockBit 5.0?
LockBit 5.0 is multi-platform with enhanced anti-analysis, randomized 16-character file extensions, faster encryption, and a rebuilt affiliate program requiring a $500 Bitcoin deposit.
What systems does LockBit 5.0 target?
Roughly 80% of observed builds target Windows and about 20% target ESXi or Linux, so virtualization infrastructure is squarely in scope.
Can law enforcement stop LockBit again?
A prior takedown disrupted but did not end the group. Whether LockBit sustains its comeback depends on avoiding a second disruption and keeping affiliates confident the brand is not compromised.
