Ransomware variant poses heightened risk to hospitals

Advertisement

The Health Information Sharing and Analysis Center, a nonprofit organization that works to share threat intelligence, issued an alert Oct. 1 regarding LockBit 5.0, a ransomware variant that represents an elevated risk to healthcare and other enterprises.

The variant is the latest iteration of the ransomware-as-a-service group, which resurfaced in September after a law enforcement disruption earlier in 2025. The group has expanded its cross-platform capabilities to target Windows, Linux and VMware ESXi environments, according to the alert.

LockBit 5.0 has enhanced obfuscation and evasion techniques, improved flexibility for affiliates, and the ability to encrypt entire virtual infrastructures. The ransomware appends randomized 16-character file extensions and clears event logs while terminating 63 security services to hinder detection and recovery.

Health-ISAC said analysis confirms the variant builds on LockBit 4.0’s codebase and demonstrates the group’s technical evolution. The organization advised members to reassess their defenses, strengthen protections for ESXi hosts and implement layered security measures to mitigate risk.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement