GodDamn Ransomware Attack Uses PsExec Lateral Movement and NirSoft Toolkit for Credential Theft
ID: 642deecb-daec-51c2-9c9b-76bcfb3a01f6
STIX ID: report--642deecb-daec-51c2-9c9b-76bcfb3a01f6
Feed Name: GBHackers
The report analyzes a late-May/early-June 2026 targeted GodDamn ransomware campaign linked to the Hyadina developer cluster (rebrands: Monster → Beast → GodDamn). Operators established manual access via AnyDesk, harvested credentials using Mimikatz and multiple NirSoft utilities, used PsExec for lateral movement, deployed a signed malicious kernel driver (PoisonX) to subvert endpoint defenses and disable real-time protection, and encrypted files on at least ten hosts — sometimes using the victim’s organization name as the extension.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
