Monster is a ransomware family associated with the threat actor and ransomware-as-a-service operation tracked as Hyadina. First observed in 2022, it is the earliest known member of a lineage that later rebranded into Beast and then GodDamn, with researchers reporting significant code and tradecraft overlap across the three iterations. Early Monster samples were described as Delphi-based and focused on 32-bit Windows systems, while the broader Hyadina operation reportedly avoided victims in Commonwealth of Independent States countries and primarily targeted organizations in the United States.
Monster is part of a mature intrusion workflow rather than a simple smash-and-encrypt operation. Across campaigns linked to this lineage, operators have used remote administration software for hands-on access, credential theft utilities including NirSoft tools and Mimikatz, network reconnaissance tools, and PsExec for lateral movement before ransomware deployment. The family’s successors also demonstrated increasingly aggressive defense evasion, including disabling security products and, in later iterations, use of a malicious signed kernel driver to impair endpoint protections prior to encryption. This progression indicates sustained development by the same operator set rather than an unrelated family.
Victimology associated with the Hyadina ecosystem includes healthcare, manufacturing, education, and other enterprise sectors. Monster’s operational model and subsequent evolution into Beast and GodDamn place it within a continuing ransomware development track characterized by credential access, expansion across Windows environments, and encryption for impact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hyadina has operated as a ransomware-as-a-service (RaaS) group for approximately four years, evolving its malware from earlier variants known as Beast and Monster to its current GodDamn locker.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier ransomware variant associated with Hyadina before the group moved to GodDamn.
Earlier ransomware family from 2022 that the article links by lineage and code overlap to Beast and GodDamn.
An earlier ransomware family in the same lineage that emerged in November 2022 and later rebranded to Beast.
An earlier ransomware family in the reported evolution chain leading to Beast and then GodDamn.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.