Cybersecurity

🔥 LockBit 5.0 Slips Up: Ransomware Gang’s Secret Server Infrastructure Exposed in Rare Operational Meltdown

December 13, 20252 min read

The cybercrime world just watched LockBit 5.0 — one of the most notorious ransomware groups on the planet — trip over its own feet.

Researchers have uncovered critical infrastructure details tied directly to LockBit’s latest operations, including:

  • IP Address: 205.185.116.233

  • Domain: karma0.xyz — the group’s newest leak site

For a threat group obsessed with stealth, this is a catastrophic OPSEC failure.

The discovery was first broadcast by cybersecurity researcher Rakesh Krishnan on December 5, exposing the server hosted under AS53667 (PONYNET) — a network infamous for harboring malware ops, botnets, and other cybercriminal ecosystems.

And the cherry on top?

The exposed server casually displays a DDoS protection splash page branded “LOCKBITS.5.0.”

That’s like a bank robber wearing a neon jacket with his name on it.


🔎 Tracking the Ransomware Nerve Center

Domain records for karma0.xyz reveal:

  • Registered: April 12, 2025

  • Expires: April 2026

  • Protected via Cloudflare and Namecheap

  • Iceland listed as the contact location

  • Domain transfer locked — a sign they’re bracing for takedowns

But the real shock came from security scans on the exposed server.


🚨 Open Ports = Open Season for Attackers

Researchers found LockBit’s infrastructure riddled with exposed services:

🎯 High-Risk Ports Discovered

  • Port 21: FTP server

  • Port 80: Apache/2.4.58 (Win64) with OpenSSL/3.1.3 + PHP 8.0.30

  • Port 3389: Remote Desktop Protocol (RDP!) on host WINDOWS-401V6QI

  • Port 5000: HTTP

  • Port 5985: WinRM

  • Port 47001: Additional HTTP service

  • Port 49666: File server

When the ransomware gang is the one with poor cybersecurity hygiene?
That’s a plot twist even Hollywood didn’t see coming.

These exposed attack surfaces could let rival threat actors — or law enforcement — pivot deeper into LockBit’s infrastructure.


🧬 Inside LockBit 5.0: Faster, Stealthier, Scarier

LockBit 5.0, first spotted in September 2025, packs features including:

  • Cross-platform targeting: Windows, Linux, ESXi

  • Randomized extension encryption

  • Geo-based evasion (skipping Russian systems, as always)

  • XChaCha20 accelerated encryption

  • SmokeLoader used for stealthy deployment

Despite law enforcement takedowns, LockBit keeps evolving — but this leak shows that even top-tier criminal gangs get sloppy.


🛡️ Defensive Measures: Block These Immediately

Security teams should take action now:

🚫 Block the IP: 205.185.116.233
🚫 Block the domain: karma0.xyz
🔍 Monitor for attempted connections or IOC matches
🧩 Add rules to SIEM/SOAR detections

LockBit’s misstep doesn’t mean they’re slowing down — but it does give defenders a rare glimpse behind the curtain.


Elliptic Systems’ Take

LockBit 5.0 is still one of the world’s most operationally aggressive ransomware groups, but this blunder reminds us:

💡 Even elite threat actors bleed.
💡 Every exposed asset is an opportunity for defenders.
💡 And ransomware gangs aren’t invincible — especially when their servers look like Swiss cheese.

Eric Stefanik

Eric Stefanik

Ai Consultant | Best-selling Author | Speaker | Innovator | Leading Cybersecurity Expert

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog