logo

New Ransomware Exploits Malicious Driver to Remove Cybersecurity Protections

ID: 145d42e0-afdb-520b-a498-ca2b7d7863ff

STIX ID: report--145d42e0-afdb-520b-a498-ca2b7d7863ff

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-07-10

Date Updated: 2026-07-19

...
...

Symantec researchers report on GodDamn, the latest Hyadina ransomware variant observed in 2026, which leverages a Microsoft-signed malicious kernel driver (PoisonX) to terminate security products, uses AnyDesk for persistence, deploys credential-stealing tools like NirSoft and Mimikatz to escalate access, and then encrypts files for ransom; the report highlights increased defensive evasion and continued development by the threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.