GodDamn is a financially motivated ransomware operation associated with the Hyadina cybercrime actor and assessed as the latest rebrand in the Monster -> Beast -> GodDamn lineage. Monster emerged in 2022, Beast followed as an evolved successor, and GodDamn appeared in 2026 as the third known iteration. The operation is notable for prioritizing defense evasion before encryption, particularly through use of the PoisonX malicious kernel driver in a bring-your-own-vulnerable-driver-style chain to disable or blind endpoint protection tools. Reported tradecraft also includes use of a fake Symantec-themed binary to impair defenses, remote access software for hands-on-keyboard access, credential-harvesting utilities derived from NirSoft tools, Mimikatz for credential theft, and PsExec for lateral movement and remote execution at scale. Observed intrusions show a multi-stage enterprise ransomware workflow: remote access establishment, credential theft from browsers, Windows credential stores, cached domain credentials, email clients, wireless profiles, and other local sources; network traffic capture; lateral movement across reachable hosts; persistence through auto-start services; and broad ransomware deployment after a dwell period. The operators have been observed repeating this sequence across multiple hosts in a short time window, indicating coordinated domain-wide operations rather than single-system encryption. Encrypted files are renamed with victim-specific extensions, and victims are directed to negotiate through email or qTox. The actor's tooling and procedures align with common big-game ransomware tradecraft focused on full-network compromise, data theft, and encryption. High-confidence reporting ties GodDamn to financially motivated cybercrime rather than state-sponsored activity. Known related names in the lineage include Monster and Beast; the developer or operator attribution associated with this lineage is Hyadina.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated ransomware operators using a signed malicious kernel driver (PoisonX/g11.sys) in a BYOVD-style defense-evasion chain, alongside a fake Symantec binary, AnyDesk, PsExec, and NirSoft-based credential theft before encrypting victim systems.
Conducting enterprise ransomware intrusions using AnyDesk for remote access, NirSoft tools and Mimikatz for credential theft, PoisonX for defense evasion, and PsExec for lateral movement before encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.