The Health Information Sharing and Analysis Center, a nonprofit organization that works to share threat intelligence, issued an alert Oct. 1 regarding LockBit 5.0, a ransomware variant that represents an elevated risk to healthcare and other enterprises. The variant is the latest iteration of the ransomware-as-a-service group, which resurfaced in September after a law enforcement disruption earlier in 2025. The group has expanded its cross-platform capabilities to target Windows, Linux and VMware ESXi environments, according to the alert.
LockBit 5.0 has enhanced obfuscation and evasion techniques, improved flexibility for affiliates, and the ability to encrypt entire virtual infrastructures. The ransomware appends randomized 16-character file extensions and clears event logs while termin