Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

LockBit 5.0: the comeback nobody wanted

Ransomnews Research TeamBy Ransomnews Research TeamJuly 17, 2026Updated:July 18, 2026No Comments4 Mins Read75 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
LockBit 5.0: the comeback nobody wanted, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

LockBit is back. After the 2024 Operation Cronos takedown gutted its infrastructure, the group relaunched as LockBit 5.0 in September 2025 and, by June 2026, had climbed to roughly 7% of tracked ransomware attacks, up from about 1% in May. The new build is multi-platform, faster, and hardened against analysis, with randomized file extensions and a revamped affiliate program. On a single day in mid-July 2026 the operation claimed nine victims, concentrated in hospitality. LockBit’s return is the clearest test yet of whether a disrupted brand can rebuild trust with affiliates.

Who is LockBit?

LockBit is a ransomware-as-a-service operation first seen in 2019 that became the world’s most prolific ransomware brand before law enforcement disrupted it in February 2024 under Operation Cronos. We covered that disruption and its aftermath in LockBit, two years after Operation Cronos. The 5.0 relaunch is the group’s attempt to reclaim the position it lost, and its June 2026 numbers show the effort gaining traction. Track new listings on the Ransomtracker feed.

How big is the resurgence?

The June 2026 data is the headline. Check Point tracking put LockBit at around 7% of attacks that month, a sharp jump from roughly 1% in May, and daily leak-site monitoring recorded LockBit 5.0 claiming nine victims on a single day in mid-July, largely in the hospitality sector. That trajectory does not restore LockBit to its pre-Cronos dominance, but it reverses the post-takedown decline and signals that affiliates are returning to a brand many had written off.

LOCKBIT // DISRUPTION TO COMEBACK Feb 2024OperationCronos Sep 2025LockBit 5.0relaunch May 2026~1% ofattacks Jun 2026~7% ofattacks LOCKBIT 5.0: WHAT CHANGED – Multi-platform: ~80% Windows builds, ~20% ESXi/Linux – Enhanced anti-analysis, randomized 16-character extensions – Faster encryption, individualized affiliate panels ($500 BTC deposit) Claimed 9 victims in one day, mid-July 2026 (hospitality-heavy)

What is new in LockBit 5.0?

The 5.0 build is a technical refresh aimed at reliability and evasion. It ships as a multi-platform toolkit, roughly 80% of observed builds targeting Windows and about 20% ESXi or Linux, with enhanced anti-analysis features, randomized 16-character file extensions, and faster encryption. The affiliate program was rebuilt with individualized panels and a $500 Bitcoin deposit to join, a structure designed to rebuild an operator base that scattered after Cronos. The randomized extensions complicate signature-based detection and victim triage alike.

Can a disrupted brand really come back?

That is the open question LockBit 5.0 is answering in real time. Law-enforcement takedowns are meant to destroy trust as much as infrastructure: affiliates fear that a compromised brand is a honeypot. LockBit’s June surge suggests some operators have decided the money outweighs the risk. Whether that holds depends on whether the group can avoid a second disruption and keep paying affiliates reliably. For defenders, the lesson is that a takedown buys time, not permanence, and detection has to keep pace with a rebranded, retooled version of a familiar threat.

How to defend against LockBit 5.0

The fundamentals hold. Close the common entry points, exposed remote access, unpatched edge devices, and phishable credentials, and enforce phishing-resistant multi-factor authentication. Protect ESXi and Linux hosts, since a fifth of LockBit 5.0 builds target them. Keep offline, tested backups so encryption is recoverable, and treat any nine-in-a-day surge in leak-site listings as a signal to review exposure in the sectors being hit. Endpoint controls that catch the pre-encryption phase are covered in our business ransomware protection guide.

Frequently asked questions

Is LockBit still active in 2026?

Yes. LockBit relaunched as version 5.0 in September 2025 and grew to roughly 7% of tracked attacks by June 2026, reversing its post-takedown decline.

What happened to LockBit in Operation Cronos?

In February 2024, a law-enforcement coalition disrupted LockBit’s infrastructure under Operation Cronos, seizing servers and damaging the brand. LockBit 5.0 is the group’s attempt to rebuild.

What is different about LockBit 5.0?

LockBit 5.0 is multi-platform with enhanced anti-analysis, randomized 16-character file extensions, faster encryption, and a rebuilt affiliate program requiring a $500 Bitcoin deposit.

What systems does LockBit 5.0 target?

Roughly 80% of observed builds target Windows and about 20% target ESXi or Linux, so virtualization infrastructure is squarely in scope.

Can law enforcement stop LockBit again?

A prior takedown disrupted but did not end the group. Whether LockBit sustains its comeback depends on avoiding a second disruption and keeping affiliates confident the brand is not compromised.

Sources and further reading

  • Check Point: June 2026 attack volumes and LockBit’s rise (July 9, 2026)
  • Help Net Security: LockBit 5.0 targets Windows, Linux, ESXi
  • Dark Web Informer: Ransomware update (July 11, 2026)
  • Ransomnews: LockBit, two years after Operation Cronos
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleDeutsche Bank breached via supplier as Unsafe gang leaks data
Next Article ShinyHunters’ Salesforce extortion wave hits Fluke, Ingram
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Deadlock: ransomware that hides its C2 on the blockchain

July 18, 2026

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

DragonForce: the cartel that absorbed its rivals

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.