PoisonX is a malicious Windows kernel driver used to disable or degrade endpoint security controls from kernel mode. It is notable for carrying a valid Microsoft Hardware Compatibility signature in observed campaigns, allowing it to load as a trusted driver on Windows systems. Once active, PoisonX has been observed terminating security-related processes, removing user-mode API hooks used by EDR products, and in some reporting exposing an IOCTL-based interface that enables arbitrary process termination from user mode. Variants and related reporting also describe its use for hiding malware activity and interfering with security telemetry at the kernel level.
PoisonX has been used in multiple intrusion contexts during 2026. It was prominently deployed by the Hyadina ransomware operation as part of GodDamn ransomware attacks, where operators used it before encryption to blind endpoint defenses, alongside tools such as AnyDesk, PsExec, Mimikatz, and NirSoft credential-harvesting utilities. In those intrusions, PoisonX functioned as a defense-evasion enabler that helped attackers maintain access, steal credentials, move laterally, and prepare victim environments for ransomware deployment.
PoisonX was also observed in spearphishing campaigns targeting organizations in Japan and China, where it was delivered with PXDropper and the modular 10FXRAT remote access trojan. In that activity, the infection chain used phishing lures and downloader or sideloading stages to install the driver and a RAT, after which the malware stack provided remote access, persistence, credential theft, keylogging, exfiltration, and proxying capabilities. Later campaign variants reportedly rotated away from PoisonX to other signed drivers, indicating that the operators treated the driver as one interchangeable component in a broader defense-evasion toolkit.
The malware is best understood as a purpose-built malicious driver rather than a legitimate driver merely repurposed through classic BYOVD abuse. Its operational role is to neutralize host defenses so companion malware or hands-on-keyboard operators can proceed with post-compromise activity more safely. Observed use spans financially motivated ransomware operations and separate espionage-leaning intrusion activity, but no single threat actor attribution is established across all PoisonX use cases.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
PoisonX is a signed Windows kernel driver observed in an April 2026 spear-phishing campaign against organizations in Japan and China.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The following day, the attackers deployed an executable named symantec.exe, which installed a kernel-mode driver called PoisonX.
この攻撃では、「PoisonX」と呼ばれるカーネルドライバと遠隔操作機能を持つ「10FXRAT(別名:PoisonX RAT)」が悪用されていることを確認しています。
24 distinct techniques documented for this family, organized by ATT&CK tactic.
...the Microsoft-signed PoisonX kernel driver to disable endpoint security through a BYOVD-style defense evasion technique before deploying the ransomware.
その後、ファイル名と同じ名称でWindowsサービスとして登録し、このサービスを起動します。... 「DevCfgCC.sys」というファイル名で永続化ディレクトリへ書き出し、OSの起動時に自動的に読み込まれるよう、システムにサービスとして登録します。
The following day, the attackers deployed an executable named symantec.exe, which installed a kernel-mode driver called PoisonX. Running in the Windows kernel gives a driver the highest level of system privileges.
マルウェア内部にハードコードされている暗号化された10FXRAT関連ファイル...を、Incremental XORを用いて復号します。
StartPayload resolves APIs dynamically, initializes direct syscall helpers, binds Winsock, and loads any cached plugins from disk.
First, the operators staged a defense-evasion tool disguised as a Symantec product.
これを受け取ったドライバは、WindowsのカーネルAPIや、正規のネットワーク監視ドライバ(¥Driver¥nsiproxy、¥Device¥Tcpなど)をフックし、指定されたPIDのプロセス情報と通信記録をシステムから除外します。これにより、OSのプロセス一覧から自身の存在を消し去り、タスクマネージャーやEDR等の各種システム監視ツールから、プロセスおよびC2サーバとの不正な通信活動を隠蔽することが可能となります。
the signed host side-loads the attacker DLL, which decrypts the bundled cache to stage the driver and RAT.
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Microsoft-signed Windows kernel driver used to terminate security-related processes and remove user-mode API hooks used by EDR products, thereby disabling endpoint protections prior to ransomware deployment.
A malicious kernel driver used by the GodDamn ransomware strain to terminate or disable endpoint security defenses before encryption.
A malicious Microsoft-signed kernel driver used to kill antivirus/EDR processes, strip security agents of required rights, or tamper with kernel notification records so defenses stop receiving events and go blind.
A malicious Microsoft-signed kernel driver used to disable endpoint defenses by killing security processes and removing user-mode API hooks before ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.