GodDamn is a Windows ransomware family first publicly observed in 2026 and assessed to be the latest rebrand in the Monster-to-Beast-to-GodDamn lineage associated with the Hyadina ransomware-as-a-service operation. The family has been linked through code overlap and shared tradecraft to earlier Monster and Beast variants, and Hyadina has been reported to focus primarily on organizations in the United States while avoiding victims in former Soviet countries. Reported victim sectors across this lineage include healthcare, manufacturing, and education.
GodDamn is notable for pairing conventional ransomware intrusion tradecraft with aggressive pre-encryption defense evasion. In observed intrusions, operators used the PoisonX kernel driver, a malicious driver carrying a valid Microsoft Hardware Compatibility signature, to interfere with endpoint protection before encryption. PoisonX has been reported to terminate security processes, remove user-mode API hooks used by EDR products, and otherwise reduce security visibility at the kernel level. Operators also used a fake security-themed executable to deploy the driver and disable Windows Defender protections.
The ransomware campaigns attributed to this family have relied heavily on legitimate and dual-use tooling after initial compromise. Observed activity includes remote access through AnyDesk, credential theft using Mimikatz and numerous NirSoft utilities, network reconnaissance and traffic capture, and lateral movement with PsExec. Attackers established persistence by installing remote access software as auto-start services and then expanded to multiple hosts before launching encryption. In documented cases, the initial access vector was not established, but the operational pattern shows a deliberate dwell period focused on credential collection, environment preparation, and spread prior to impact.
During encryption, GodDamn has been observed renaming files either with a victim-specific extension or with the .God8Damn extension, followed by ransom instructions directing victims to contact the operators through email or qTox. The family represents an evolution toward more mature enterprise ransomware operations that combine credential theft, persistence, lateral movement, and kernel-level defense evasion before file encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hyadina has operated as a ransomware-as-a-service (RaaS) group for approximately four years, evolving its malware from earlier variants known as Beast and Monster to its current GodDamn locker.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Perspective The observed behavior aligns with several MITRE ATT&CK techniques, including: ... Windows Management Instrumentation
MITRE ATT&CK Perspective The observed behavior aligns with several MITRE ATT&CK techniques, including: ... Registry Modification
The initial infection vector could not be determined, with the attacker installing AnyDesk on the first victim machine in the Music folder, suggesting a manual action by an attacker with prior access.
MITRE ATT&CK Perspective The observed behavior aligns with several MITRE ATT&CK techniques, including: ... Process Injection
This binary dropped PoisonX, a malicious kernel driver signed by “Microsoft Windows Hardware Compatibility Publisher.” The PoisonX driver works similarly to a signed vulnerable driver in bring-your-own-vulnerable-driver (BYOVD) attacks
AnyDesk is registered as an auto-start Windows service to survive reboots.
After deploying PoisonX for detection evasion, the GodDamn ransomware attacker deployed a comprehensive suite of 14 credentials-harvesting tools comprising Mimikatz and 13 NirSoft tools
The attacker also deployed NetScan, which could be used to map the victim’s network.
Defense Evasion GodDamn employs multiple techniques to avoid detection. These include: Kernel driver abuse Security process termination
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware payload used by the Hyadina group to encrypt victim systems after the attackers disable endpoint protections, steal credentials, and move laterally.
A ransomware strain that uses the PoisonX kernel driver to disable endpoint defenses prior to encrypting victim systems.
Ransomware assessed as a rebrand in the Monster -> Beast -> GodDamn lineage. It disables or blinds endpoint defenses before encryption, using the Microsoft-signed PoisonX kernel driver in a BYOVD-style attack, a fake Symantec user-mode killer, credential theft via NirSoft tools, and lateral movement with PsExec and AnyDesk.
Ransomware deployed in a June 2026 attack; the article describes it as a rebranding of Beast with significant code overlap and as the final payload used after credential collection and defense evasion activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.