logo

'GodDamn' Ransomware Uses BYOVD to Smite US Companies

ID: 055c4262-a961-5911-ad8c-fffcf7f9cdf9

STIX ID: report--055c4262-a961-5911-ad8c-fffcf7f9cdf9

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-07-09

Date Updated: 2026-07-17

Author: Nate Nelson

...
...

Hyadina, a ransomware-as-a-service operation, has been observed deploying a new locker named "GodDamn" against U.S. organizations and using a malicious, Microsoft-signed kernel driver called PoisonX to disable endpoint defenses. The attackers combine legitimate remote-management tools (AnyDesk, RMM), a suite of open-source credential stealers (mostly NirSoft tools and Mimikatz), and lateral movement utilities to entrench and encrypt victims, highlighting the risk posed by signed vulnerable drivers and the lagging Microsoft blocklist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.