New Ransomware Exploits Malicious Driver to Remove Cybersecurity Protections
ID: 145d42e0-afdb-520b-a498-ca2b7d7863ff
STIX ID: report--145d42e0-afdb-520b-a498-ca2b7d7863ff
Feed Name: Infosecurity Magazine (News)
Threat Score
Symantec researchers report on GodDamn, the latest Hyadina ransomware variant observed in 2026, which leverages a Microsoft-signed malicious kernel driver (PoisonX) to terminate security products, uses AnyDesk for persistence, deploys credential-stealing tools like NirSoft and Mimikatz to escalate access, and then encrypts files for ransom; the report highlights increased defensive evasion and continued development by the threat actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
