LevelBlue Acquires Fortra’s Alert Logic MDR Business, Strengthening Position as Global MDR Leader. Learn More
Access immediate incident response support, available 24/7
Access immediate incident response support, available 24/7
LevelBlue Acquires Fortra’s Alert Logic MDR Business, Strengthening Position as Global MDR Leader. Learn More
The prolific LockBit ransomware-as-a-service (RaaS) group shows its dedication to evolutionary tactics and cross-platform attack capabilities in the latest iteration of its namesake malware, LockBit 5.0.
Our analysis of 19 LockBit 5.0 samples shows that it uses ChaCha20, a swift and stealthy 256-bit stream cipher, to encrypt files and data. This is a departure from its use of an Advanced Encryption Software (AES) key in earlier versions, such as in LockBit 2.0 and LockBit 3.0.
The use of ChaCha20 is an attempt to make detection more challenging for security defenders. As of writing, the sample we analyzed has a detection score of 1/65 on VirusTotal.

Figure 1. VirusTotal detection results for the LockBit 5.0 sample we analyzed as of writing
LockBit 5.0 uses the same encryption algorithm for Windows, Linux, and ESXi environments. However, we observed that it uses different system-specific behaviors to function optimally in each environment. This highlights how LockBit actors deliver highly targeted and evolved variants to maximize damage to victims.
Our full technical deep-dive, coming in a three-part blog series, of LockBit 5.0 samples across Windows, Linux, and ESXi environments provides comprehensive information on the following noteworthy observations:
Our full report provides the full technical breakdown of LockBit 5.0 samples for Windows, Linux, and ESXi environments, as well as the samples’ Indicators of Compromise (IOCs), and MITRE ATT&CK mapping information. Aside from providing essential security recommendations that defenders can adopt to keep their environment secure, our report also provides details on how Cybereason, A LevelBlue Company, protects users against LockBit 5.0 attacks.
You can read Part 1 of the three-part series here.
LevelBlue is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.