Just in:
Delhi tops SIR deletion in percentage, Maharashtra in absolute numbers // Qatar economy contracts 7% as energy output slumps // Haldwani purification row: Caste back on political centre-stage // Putin holds talks with Pezeshkian in Bishkek // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // Alpha Dhabi lifts MICAD commitment to $1 billion // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Dubai hotel provides free public co-working space // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // Adobe widens Saudi AI access with $4 billion programme // India plans own orbital space outpost, second after China // What Shein’s $27bn IPO means for Mubadala // Russia brings cryptocurrency market law into force // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Midea to Showcase SpaceMaster Series with Graphene Technology at IFA 2026 // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // LatAm gushers and possible Venezuela exit a nightmare for Opec //

LockBit 5.0 infrastructure leak reveals exposed servers and domains

Security researchers have uncovered critical infrastructure details tied to the ransomware operation LockBit 5.0, exposing a publicly accessible server and domain used by the gang. The server, identified by IP address 205.185.116.233, and the domain karma0. xyz have been linked to the group’s latest leak-site. The disclosure, first shared by cybersecurity researcher Rakesh Krishnan on 5 December 2025, represents a major operational security failure for the ransomware collective.

The exposed server is hosted under AS53667, a network previously flagged for hosting illicit activities. Its web interface displays a DDoS protection banner labelled “LOCKBITS.5.0,” underscoring its role in LockBit’s infrastructure. WHOIS records show that karma0. xyz was registered in April 2025, with Cloudflare nameservers and privacy protections listing a Reykjavík contact address, while its domain status restricts transfers—suggesting attempts to harden control under scrutiny.

Port scans of 205.185.116.233 reveal multiple open services, including FTP on port 21, Apache HTTP on port 80, RDP on port 3389, WinRM on port 5985, and various file-sharing services. The presence of RDP access is particularly concerning, as it provides a high-risk vector for remote intrusion and could enable actors to hijack the server or use it for further attacks.

The exposure coincides with a wider resurgence of LockBit following its high-profile disruption in early 2024 under Operation Cronos. Despite that takedown—and a May 2025 leak of LockBit’s administrative panel and affiliate data—the group has bounced back with its 5.0 variant. According to security vendor Check Point Research, the group carried out multiple attacks across continents in September 2025, affecting both Windows and Linux systems, underlining that its infrastructure and affiliate network remain active.

The technical improvements in LockBit 5.0 have drawn attention from defenders and researchers. According to analysis by Flashpoint and the security firm Trend Micro, the new variant employs a two-stage modular execution model: a stealth loader followed by the main payload. It leverages techniques such as obfuscated control flow, dynamic API resolution, DLL reflection, and ETW patching to evade detection. The ransomware supports Windows, Linux and VMware ESXi platforms, offering affiliates multiplatform capabilities rarely seen in earlier versions.

LockBit 5.0’s encryption process introduces randomized 16-character file extensions and optional “invisible mode,” which omits extensions and ransom notes—making detection and recovery more difficult. The payload can also disable or terminate security services, wipe event logs after execution, and target entire network environments including virtualised systems.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Putin holds talks with Pezeshkian in Bishkek // Delhi tops SIR deletion in percentage, Maharashtra in absolute numbers // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // Adobe widens Saudi AI access with $4 billion programme // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // LatAm gushers and possible Venezuela exit a nightmare for Opec // Midea to Showcase SpaceMaster Series with Graphene Technology at IFA 2026 // Qatar economy contracts 7% as energy output slumps // Venezuela defends sovereignty after Trump oil control claim // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // The Mineral Boutique Limited Welcomes CCS Clarification and Reaffirms Asia Growth Strategy // India plans own orbital space outpost, second after China // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Xi reaches Cairo as China broadens Egypt engagement // Trump rejects munitions fears as Iran clashes resume // Apple raises evidence-destruction claims against OpenAI // Haldwani purification row: Caste back on political centre-stage // Alpha Dhabi lifts MICAD commitment to $1 billion // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 //