LockBit 5's Infrastructure Leaked Following Blog Domain Announcement
Article Content
Browse articles
LockBit 5 has had its infrastructure leaked shortly after announcing a new secure blog domain. The leak was revealed by Rakesh Krishnan on December 5, 2025, who disclosed the IP address and domain. Cybersecurity defenders are advised to block the exposed IP and domain immediately.
Ask AI about this cluster
Answers cite the sources they use
Updated 213d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track Lockbit in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PAYLOAD Ransomware Exploits Active Directory GPO for Disruption In April 2026, Kaspersky's Global Emergency Response Team (GERT) responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control via a compromised FortiGate SSL VPN account and created a malicious Group Policy Object (GPO) named PAYLOAD. This GPO…
Threat Actors Exploit Windows Shadow Copies for Ransomware and Credential Theft Cybercriminals are increasingly abusing Microsoft’s Volume Shadow Copy Service (VSS) to facilitate ransomware attacks and steal credentials. They achieve this by deleting recovery options before deploying ransomware and extracting sensitive data from protected files, including the Active Directory database. Tools such…