logo

GodDamn Ransomware Attack Uses PsExec Lateral Movement and NirSoft Toolkit for Credential Theft

ID: 642deecb-daec-51c2-9c9b-76bcfb3a01f6

STIX ID: report--642deecb-daec-51c2-9c9b-76bcfb3a01f6

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-07-09

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

The report analyzes a late-May/early-June 2026 targeted GodDamn ransomware campaign linked to the Hyadina developer cluster (rebrands: Monster → Beast → GodDamn). Operators established manual access via AnyDesk, harvested credentials using Mimikatz and multiple NirSoft utilities, used PsExec for lateral movement, deployed a signed malicious kernel driver (PoisonX) to subvert endpoint defenses and disable real-time protection, and encrypted files on at least ten hosts — sometimes using the victim’s organization name as the extension.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.