GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver — Threadlinqs Intelligence
As of 2026-07-16, GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver is a high-severity ransomware threat attributed to Hyadina, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 37 indicators of compromise.
Threat ID: TL-2026-1148 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Updated: 2026-07-16 · 2 updates · revalidated 2× · latest source
Attribution: Hyadina · FINANCIAL
Hyadina, a ransomware-as-a-service operation active since March 2022, has rebranded its locker for the third time (Monster -> Beast -> GodDamn), first documented May 21, 2026. GodDamn encrypts victim
GodDamn is the latest rebrand of the Hyadina ransomware-as-a-service operation, tracing a lineage from Monster (first observed March 2022, Delphi-written, 32-bit Windows-only, deliberately avoided CIS-region targets) to Beast (June 2024, added Linux/VMware ESXi support, stronger encryption, and multilingual builds including Chinese-language variants) to GodDamn (first documented May 21, 2026). The defining evolution in GodDamn is the integration of PoisonX (file g11.sys, SHA-256 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145d), a malicious kernel driver that its developers succeeded in getting Microsoft to sign via the Windows Hardware Compatibility Program. Because the driver carries a legitimate Microsoft signature, Windows loads it automatically once dropped by an attacker with administrator privileges, making it a textbook Bring-Your-Own-Vulnerable-Driver (BYOVD) defense-evasion tool. PoisonX operates at kernel level to terminate security-related processes, strip endpoint security agents of the rights/hooks they need to function, and tamper with kernel structures to blind AV/EDR tooling — effectively disabling Windows Defender real-time protection and other installed security products. Alongside the driver, the intrusion set deploys a user-mode decoy binary masquerading as "symantec.exe" to further mislead defenders and disable legitimate Symantec/Broadcom protections. Symantec's Threat Hunter Team investigated a real-world intrusion in which the attacker gained initial access, then spent roughly four days conducting reconnaissance, credential harvesting, and lateral movement before deploying the encryptor, ultimately reaching more than ten hosts in the environment. The toolkit is a fairly standard but comprehensive off-the-shelf RaaS affiliate loadout: PsExec for remote command execution and lateral tool transfer, AnyDesk (configured to auto-start as a Windows service) for persistent remote access, Mimikatz for credential dumping, and a large collection of NirSoft utilities (Netpass, WirelessKeyView, CredentialsFileView, MailPassView, ChromePass, PstPassword, MessengerPass, VNCPassView, OperaPassView, WebBrowserPassView, SniffPass, ExtPassword, PasswordFox) to harvest credentials from browsers, VPN clients, Wi-Fi profiles, email clients, and VNC sessions. Netscan was used for internal network discovery, and additional tools (Gmer rootkit scanner, Defender Control, IObit Unlocker) support further defense evasion and unlocking of files held open by other processes prior to encryption. Ransom communication with victims is conducted via email or the qTox encrypted messaging application, consistent with prior Hyadina operations. Notably, the PoisonX driver has also been observed adopted by a separate RaaS operation, The Gentlemen, via a related tool called GentleKiller, indicating the signed driver is being shared or resold within the ransomware-affiliate ecosystem as a commodity BYOVD defense-evasion capability. Victim targeting has expanded from Monster's CIS-avoidance policy to apparent international targeting, with GodDamn's multilingual capability (including Chinese-language support inherited from Beast) suggesting a broad affiliate targeting scope; documented intrusion activity in June 2026 targeted U.S. companies.
Weaknesses (CWE)
CWE-269, CWE-732, CWE-284, CWE-347
Target sectors: unspecified broad enterprise targeting
Target regions: united states of america, international (excluding historical CIS avoidance under Monster variant)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 37 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1133, T1569.002, T1543.003, T1133, T1548, T1211, T1562.001, T1562.002, T1553.002, T1036.005