GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses
ID: e6e6585b-3136-5028-8a2c-c933c4f49ca1
STIX ID: report--e6e6585b-3136-5028-8a2c-c933c4f49ca1
Feed Name: security.com
Symantec analysts attribute recent GodDamn ransomware activity to the Hyadina group (a rebrand lineage from Monster→Beast→GodDamn). The report details a May–June 2026 campaign where operators used AnyDesk for persistent remote access, a NirSoft-based credential-harvesting toolkit (including Mimikatz), PsExec for lateral movement, and a signed malicious kernel driver (PoisonX) to disable endpoint defenses before deploying the GodDamn encryptor; it includes numerous file-hash IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
