logo

GodDamn Ransomware Uses PoisonX to Blind Security Software

ID: 5c56a62f-c393-5e8d-97d3-b8a119ba11dd

STIX ID: report--5c56a62f-c393-5e8d-97d3-b8a119ba11dd

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-07-09

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

GodDamn is a new ransomware variant (a rebrand of Beast/Monster) used by the Hyadina group that leverages a legitimately signed malicious kernel driver called PoisonX to blind security software at the kernel level; Symantec observed attackers using AnyDesk for persistent remote access, NirSoft/Mimikatz credential harvesters, PsExec-based lateral movement, and encryption beginning June 3, 2026, with at least 10 hosts impacted during the investigated intrusion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.