News Room
16
Share
LockBit 5.0 and Termite Ransomware Surge: New Attacks Hit Financial and Mortgage Sectors
criticalThreat Intelligence

LockBit 5.0 and Termite Ransomware Surge: New Attacks Hit Financial and Mortgage Sectors

Recent intelligence confirms a spike in double-extortion activity as LockBit 5.0 targets Ethiopian banking infrastructure and the Termite group compromises a major U.S. mortgage firm.

23 September 2026Last updated 23 September 20264 min readCrowdStrike
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
Confirmed
Source:
CrowdStrike
Read Time:
4 min

Executive Summary

As of September 23, 2026, the global threat landscape is witnessing a coordinated surge in ransomware activity. Two prominent threat actors, LockBit 5.0 and the Termite group, have successfully executed high-profile breaches against critical financial and mortgage institutions. These incidents underscore the persistent threat of double-extortion models, where attackers leverage both data encryption and the threat of public data exposure to coerce victims into payment.

Threat Analysis

The current wave of attacks demonstrates a shift toward high-value targets. LockBit 5.0, a mature RaaS operation, has successfully compromised Siinqee Bank in Ethiopia, signaling an expansion of their operational reach into emerging financial markets. Simultaneously, the Termite group has targeted theLender, a U.S.-based wholesale mortgage company. Both groups utilize established double-extortion tactics, exfiltrating sensitive PII and financial records before deploying encryption payloads.

Technical Details

These attacks follow a standard RaaS lifecycle. Initial access is typically gained through credential harvesting or exploitation of edge-facing vulnerabilities. Once inside, the actors perform lateral movement using living-off-the-land (LotL) techniques to avoid detection by EDR solutions. The final stage involves the deployment of custom ransomware binaries that utilize robust encryption algorithms (e.g., AES-256/RSA-4096). The exfiltration phase is conducted via encrypted tunnels to attacker-controlled C2 infrastructure, ensuring that the threat actors maintain leverage even if the victim restores from backups.

Attribution Assessment

LockBit 5.0 continues to operate as a highly organized, professionalized RaaS entity, maintaining a global affiliate network. The Termite group, while newer, has demonstrated significant technical proficiency and a clear focus on the U.S. financial services sector. Both groups rely on Tor-based leak sites to host stolen data, a hallmark of modern cybercriminal extortion strategies.

Implications

The targeting of financial and mortgage institutions poses a severe risk to data privacy and systemic economic stability. The ability of these groups to bypass traditional security controls suggests that organizations must move beyond perimeter-based defenses. The continued success of these campaigns indicates that the RaaS business model remains highly profitable for threat actors.

Recommendations

Organizations are advised to: 1) Implement strict multi-factor authentication (MFA) across all remote access points. 2) Conduct regular, offline backups of critical data to mitigate the impact of encryption. 3) Enhance network segmentation to limit lateral movement. 4) Monitor for unauthorized data egress patterns using advanced behavioral analytics. 5) Maintain an active incident response plan that includes communication strategies for potential data leaks.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo