logo

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

ID: c831e951-a6f8-5a9f-8ce4-3f87e0bbea6b

STIX ID: report--c831e951-a6f8-5a9f-8ce4-3f87e0bbea6b

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-09

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Symantec and other vendors observed an active ransomware campaign attributed to the Hyadina group using a rebranded family called GodDamn. Operators employed a signed malicious kernel driver (PoisonX) in a BYOVD technique to neutralize security products, used credential harvesting tools and AnyDesk/PsExec for persistence and lateral movement, and encrypted files across multiple hosts in June 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.