logo

GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses

ID: e6e6585b-3136-5028-8a2c-c933c4f49ca1

STIX ID: report--e6e6585b-3136-5028-8a2c-c933c4f49ca1

Feed Name: security.com

Threat Score
85/100

Date Published: 2026-07-09

Date Updated: 2026-07-20

Author: Threat Hunter Team

...
...

Symantec analysts attribute recent GodDamn ransomware activity to the Hyadina group (a rebrand lineage from Monster→Beast→GodDamn). The report details a May–June 2026 campaign where operators used AnyDesk for persistent remote access, a NirSoft-based credential-harvesting toolkit (including Mimikatz), PsExec for lateral movement, and a signed malicious kernel driver (PoisonX) to disable endpoint defenses before deploying the GodDamn encryptor; it includes numerous file-hash IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.