Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-06

LockBit 5.0

Also known as:Dysphor1ARTX106BfpussyFutanari

As of 2026-09-28, LockBit 5.0 is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning threat intel, ransomware. Also known as Dysphor1A, RTX106, Bfpussy, Futanari. ATT&CK coverage spans 57 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1059.007 (JavaScript).

Tracked threats
21 critical · 1 high
First seen
2026-06-10
Last seen
2026-09-28
ATT&CK techniques
57across 2 of 2 threats
Related CVEs
5Referenced by its activity
2 tracked threat(s) · Categories: THREAT_INTEL, RANSOMWARE

Activity timeline

LockBit 5.0 appears in 2 tracked threats between and ; the busiest month was 2026-06 with 1 report.

ATT&CK techniques observed

57 techniques observed across 2 of 2 tracked threats · Stealth (formerly Defense Evasion) (10), Discovery (8), Execution (7), Command and Control (6), Credential Access (4), Impact (4)
  • T1005 Data from Local System — Collectionobserved in 2 of 2 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1059.007 JavaScript — Executionobserved in 2 of 2 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 2 of 2 tracked threats
  • T1490 Inhibit System Recovery — Impactobserved in 2 of 2 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 2 of 2 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 2 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1018 Remote System Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 1 of 2 tracked threats
  • T1027.006 HTML Smuggling — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 1 of 2 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1049 System Network Connections Discovery — Discoveryobserved in 1 of 2 tracked threats

Tracked threats

Related CVEs

5 CVEs referenced by tracked LockBit 5.0 activity