# Hyadina

> As of 2026-09-08, Hyadina is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning ransomware. ATT&CK coverage spans 50 techniques across 14 tactics in 2 of 2 tracked threats. Most-observed techniques: T1003 (OS Credential Dumping), T1046 (Network Service Discovery), T1133 (External Remote Services).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** RANSOMWARE
- **As of:** 2026-09-08

## ATT&CK techniques observed

50 techniques observed across 2 of 2 tracked threats. Tactics: Credential Access (9), Stealth (formerly Defense Evasion) (6), Discovery (5), Execution (5), Defense Impairment (4), Impact (4).

- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 2 of 2 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Initial Access — observed in 2 of 2 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 2 of 2 tracked threats
- [T1489](https://intel.threadlinqs.com/technique/T1489) Service Stop — Impact — observed in 2 of 2 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 2 of 2 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 2 of 2 tracked threats
- [T1003.001](https://intel.threadlinqs.com/technique/T1003.001) LSASS Memory — Credential Access — observed in 1 of 2 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 2 tracked threats
- [T1014](https://intel.threadlinqs.com/technique/T1014) Rootkit — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 1 of 2 tracked threats
- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 1 of 2 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 1 of 2 tracked threats

## Tracked threats

- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint Defenses](https://intel.threadlinqs.com/threat/TL-2026-2409) — CRITICAL
- [GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver](https://intel.threadlinqs.com/threat/TL-2026-1148) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Hyadina
