'GodDamn' Ransomware Uses BYOVD to Smite US Companies
ID: 055c4262-a961-5911-ad8c-fffcf7f9cdf9
STIX ID: report--055c4262-a961-5911-ad8c-fffcf7f9cdf9
Feed Name: Dark Reading
Hyadina, a ransomware-as-a-service operation, has been observed deploying a new locker named "GodDamn" against U.S. organizations and using a malicious, Microsoft-signed kernel driver called PoisonX to disable endpoint defenses. The attackers combine legitimate remote-management tools (AnyDesk, RMM), a suite of open-source credential stealers (mostly NirSoft tools and Mimikatz), and lateral movement utilities to entrench and encrypt victims, highlighting the risk posed by signed vulnerable drivers and the lagging Microsoft blocklist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
