Beast is a ransomware family operated as part of a ransomware-as-a-service ecosystem and associated with the threat actor tracked as Hyadina. It is assessed to be a direct evolution and rebrand of the earlier Monster ransomware family, and itself the predecessor of the later GodDamn ransomware, with significant code and tradecraft overlap across all three iterations. The family has been active since 2022 in its Monster form and was rebranded as Beast in 2024.
Beast initially targeted Windows systems and later expanded to Linux and VMware ESXi environments, reflecting a shift toward broader enterprise impact. Reported intrusions show the operators using legitimate remote administration software for hands-on access, credential theft utilities including NirSoft-based tools and Mimikatz, network discovery tooling, and PsExec for lateral movement before ransomware deployment. The group has also been observed disabling security controls and backup-related processes, deleting shadow copies, and using additional defense-evasion tooling to weaken endpoint protections prior to encryption. Beast operations have been linked to data theft as well as encryption, consistent with double-extortion ransomware activity.
The malware has been reported targeting organizations across multiple sectors, including healthcare, manufacturing, education, and industrial environments, with a primary focus on U.S. organizations while reportedly avoiding victims in CIS countries. Beast has also been described as supporting multilingual operation and improving its encryption workflow over earlier variants. Operational reporting and exposed operator infrastructure indicate reliance on common dual-use tools for reconnaissance, persistence, exfiltration, and recovery inhibition, making attribution dependent on the ransomware payload and broader campaign context rather than tooling alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hyadina has operated as a ransomware-as-a-service (RaaS) group for approximately four years, evolving its malware from earlier variants known as Beast and Monster to its current GodDamn locker.
The Beast ransomware group is a fairly new one, which sprung from another strain — the so-called Monster ransomware gang. It announced itself in 2024, and began operations as a ransomware-as-a-service (RaaS) scheme in February 2025, launching a data-leak site in July.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
BeastDoor provides process injection capabilities and several builder options, including: Notifications Startup AV-FW Kill Misc Exe Icon
The payload dynamically loads the DLL using LoadLibraryA
The Exe Icon option allows the attacker to change the payload’s icon to improve social engineering effectiveness.
BeastDoor provides process injection capabilities and several builder options, including: Notifications Startup AV-FW Kill Misc Exe Icon
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier ransomware variant associated with Hyadina before the group moved to GodDamn.
Ransomware family described as directly linked to Monster and GodDamn, with GodDamn characterized as a rebrand of Beast.
A ransomware family that rebranded from Monster in June 2024 and is described as the predecessor/rebrand lineage for GodDamn.
A ransomware family described as an intermediate evolution stage between Monster and GodDamn, reflecting improvements in tooling and evasion techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.