The Hyadina ransomware operation has deployed its newly rebranded GodDamn locker against U.S. organizations, using a signed kernel driver called PoisonX to weaken endpoint protections before encryption. Symantec linked GodDamn to the earlier Beast and Monster ransomware families, describing it as the latest rebrand in the same lineage. In the investigated intrusion, the attackers used AnyDesk for remote access, PsExec for lateral movement, and a broad credential-theft toolkit built around Mimikatz and multiple NirSoft utilities, while also using a fake Symantec-branded evasion tool to install the malicious driver.
PoisonX, signed through Microsoft’s Hardware Compatibility process, was used in a bring your own vulnerable driver-style tactic to terminate security processes and remove user-mode API hooks, reducing the effectiveness of endpoint defenses. Symantec said the attackers established persistence and unattended remote access across at least 10 hosts before ransomware binaries were detected, with suspicious AnyDesk activity preceding lateral movement and final deployment by several days. Researchers said the case shows Hyadina’s increasing reliance on dual-use and open-source tools, while also underscoring concerns that Microsoft’s vulnerable driver blocklist may not immediately cover newly identified malicious or dangerous drivers.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Gurucul released a threat research report on GodDamn ransomware that included a large set of MD5, SHA-1, and SHA-256 indicators of compromise along with corresponding detection queries for Gurucul Threat Detection and Incident Response. The report also reiterated that GodDamn is the latest Beast/Monster rebrand linked to Hyadina and uses the signed PoisonX driver for BYOVD defense evasion.
Dark Reading reported that Hyadina was using the newly rebranded GodDamn ransomware in attacks against U.S. organizations, highlighting PoisonX as a signed malicious driver used to terminate security processes and remove user-mode API hooks.
Symantec concluded that GodDamn is the latest rebrand of Beast, itself a rebrand of Monster, and attributed the ransomware line to the developer tracked as Hyadina based on overlapping tooling and tradecraft.
Symantec analyzed a June 2026 ransomware intrusion in which Hyadina used the newly observed GodDamn locker along with AnyDesk, PsExec, Mimikatz, NirSoft tools, and a fake Symantec-branded utility to deploy the signed PoisonX driver and weaken endpoint defenses.
Alpha Cyber reported that PoisonX.sys was used in an April 2026 spear-phishing campaign targeting organizations in Japan and China, where phishing emails led to PXDropper installing the signed driver and the 10FXRAT malware. The report also disclosed that PoisonX exposes IOCTL 0x22E010 to terminate EDR and AV processes from kernel mode, including PPL-protected sensors.
Ransomware binaries were first detected after the attackers had established persistence and unattended remote access across at least 10 hosts in the victim network.
The operators used tools including PsExec to move laterally after initial access, broadening their presence across the environment.
Symantec reported that the investigated ransomware intrusion began with suspicious AnyDesk activity, indicating the attackers' initial access or early foothold in the victim environment.
Alpha Cyber reported that the GodDamn ransomware campaign was first observed in the wild on 2026-05-21. The activity involved the Hyadina-linked Beast/Monster/GodDamn lineage and PoisonX-based defense evasion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 40 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
15 references tracked. Mallory keeps watching after this page renders.
alpha-cyber.com
Open sourcesecurityonline.info
Open sourcecyberveille.ch
Open sourceinfosecurity-magazine.com
Open sourcedarkreading.com
Open sourcesecurity.com
Open sourcealpha-cyber.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.