
LockBit 5.0 and Termite Ransomware Surge: New Attacks Hit Financial and Mortgage Sectors
Recent intelligence confirms a spike in double-extortion activity as LockBit 5.0 targets Ethiopian banking infrastructure and the Termite group compromises a major U.S. mortgage firm.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- CrowdStrike
- Read Time:
- 4 min
Executive Summary
As of September 23, 2026, the global threat landscape is witnessing a coordinated surge in ransomware activity. Two prominent threat actors, LockBit 5.0 and the Termite group, have successfully executed high-profile breaches against critical financial and mortgage institutions. These incidents underscore the persistent threat of double-extortion models, where attackers leverage both data encryption and the threat of public data exposure to coerce victims into payment.
Threat Analysis
The current wave of attacks demonstrates a shift toward high-value targets. LockBit 5.0, a mature RaaS operation, has successfully compromised Siinqee Bank in Ethiopia, signaling an expansion of their operational reach into emerging financial markets. Simultaneously, the Termite group has targeted theLender, a U.S.-based wholesale mortgage company. Both groups utilize established double-extortion tactics, exfiltrating sensitive PII and financial records before deploying encryption payloads.
Technical Details
These attacks follow a standard RaaS lifecycle. Initial access is typically gained through credential harvesting or exploitation of edge-facing vulnerabilities. Once inside, the actors perform lateral movement using living-off-the-land (LotL) techniques to avoid detection by EDR solutions. The final stage involves the deployment of custom ransomware binaries that utilize robust encryption algorithms (e.g., AES-256/RSA-4096). The exfiltration phase is conducted via encrypted tunnels to attacker-controlled C2 infrastructure, ensuring that the threat actors maintain leverage even if the victim restores from backups.
Attribution Assessment
LockBit 5.0 continues to operate as a highly organized, professionalized RaaS entity, maintaining a global affiliate network. The Termite group, while newer, has demonstrated significant technical proficiency and a clear focus on the U.S. financial services sector. Both groups rely on Tor-based leak sites to host stolen data, a hallmark of modern cybercriminal extortion strategies.
Implications
The targeting of financial and mortgage institutions poses a severe risk to data privacy and systemic economic stability. The ability of these groups to bypass traditional security controls suggests that organizations must move beyond perimeter-based defenses. The continued success of these campaigns indicates that the RaaS business model remains highly profitable for threat actors.
Recommendations
Organizations are advised to: 1) Implement strict multi-factor authentication (MFA) across all remote access points. 2) Conduct regular, offline backups of critical data to mitigate the impact of encryption. 3) Enhance network segmentation to limit lateral movement. 4) Monitor for unauthorized data egress patterns using advanced behavioral analytics. 5) Maintain an active incident response plan that includes communication strategies for potential data leaks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Emperador Ransomware Group Escalates Operations with Targeted Attack on BAYMER

Emperador Ransomware Group Escalates Double Extortion Tactics Targeting US Industrial Sector

