# LockBit 5.0

> As of 2026-09-28, LockBit 5.0 is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning threat intel, ransomware. Also known as Dysphor1A, RTX106, Bfpussy, Futanari. ATT&CK coverage spans 57 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1059.007 (JavaScript).

- **Tracked threats:** 2
- **Categories:** THREAT_INTEL, RANSOMWARE
- **Also known as:** Dysphor1A, RTX106, Bfpussy, Futanari
- **As of:** 2026-09-28

## ATT&CK techniques observed

57 techniques observed across 2 of 2 tracked threats. Tactics: Stealth (formerly Defense Evasion) (10), Discovery (8), Execution (7), Command and Control (6), Credential Access (4), Impact (4).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1059.007](https://intel.threadlinqs.com/technique/T1059.007) JavaScript — Execution — observed in 2 of 2 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 2 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 2 of 2 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 2 of 2 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 2 of 2 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 1 of 2 tracked threats
- [T1027.006](https://intel.threadlinqs.com/technique/T1027.006) HTML Smuggling — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 1 of 2 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1049](https://intel.threadlinqs.com/technique/T1049) System Network Connections Discovery — Discovery — observed in 1 of 2 tracked threats

## Tracked threats

- [ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and Multiple Unverified Data-Breach Claims](https://intel.threadlinqs.com/threat/TL-2026-2730) — HIGH
- [Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0758) — CRITICAL

## Related CVEs

5 CVEs referenced by tracked LockBit 5.0 activity.

- [CVE-2025-61884](https://intel.threadlinqs.com/cve/CVE-2025-61884)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/LockBit%205.0
