GodDamn Ransomware Uses PoisonX to Blind Security Software
ID: 5c56a62f-c393-5e8d-97d3-b8a119ba11dd
STIX ID: report--5c56a62f-c393-5e8d-97d3-b8a119ba11dd
Feed Name: Security Affairs
Threat Score
GodDamn is a new ransomware variant (a rebrand of Beast/Monster) used by the Hyadina group that leverages a legitimately signed malicious kernel driver called PoisonX to blind security software at the kernel level; Symantec observed attackers using AnyDesk for persistent remote access, NirSoft/Mimikatz credential harvesters, PsExec-based lateral movement, and encryption beginning June 3, 2026, with at least 10 hosts impacted during the investigated intrusion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
