lockbit5
Unverified threat-actor claim — not a regulatory filing
Attribution, victim identity, and counts shown here derive from lockbit5's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Sanctions caution: lockbit5 carries US sanctions exposure — OFAC has designated the group or its operators. Public reporting is permitted, but any payment or material support may violate sanctions. Consult counsel before engaging.
According to ransomware.live, the group claims:
LockBit 5.0 ("ChuongDong") emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform payloads targeting Windows, Linux, and VMware ESXi with enhanced evasion capabilities and continuing the RaaS affiliate model of its predecessors.
Source: Ransomware.live