logo

Koxic Ransomware Deep-dive Analysis

ID: 9d3bee19-029f-5652-a906-d1a2747a4d11

STIX ID: report--9d3bee19-029f-5652-a906-d1a2747a4d11

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

This report analyzes the Koxic ransomware sample, detailing its infection and post-compromise behaviors — including disabling Windows Defender, terminating security processes, deleting shadow copies, disabling database services, stealing system information, privilege manipulation, and encrypting files with a ".KOXIC_KLIBD" extension — and provides IOCs (SHA256, extortion email), MITRE ATT&CK mappings, and mitigation recommendations for backups, patching, and endpoint protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.