GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
ID: c831e951-a6f8-5a9f-8ce4-3f87e0bbea6b
STIX ID: report--c831e951-a6f8-5a9f-8ce4-3f87e0bbea6b
Feed Name: The Hacker News
Threat Score
Symantec and other vendors observed an active ransomware campaign attributed to the Hyadina group using a rebranded family called GodDamn. Operators employed a signed malicious kernel driver (PoisonX) in a BYOVD technique to neutralize security products, used credential harvesting tools and AnyDesk/PsExec for persistence and lateral movement, and encrypted files across multiple hosts in June 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
