GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver
GodDamn Ransomware (Hyadina) (TL-2026-1148), also tracked as GodDamn ransomware, is a high-severity ransomware operation, first published 2026-07-09 and last reviewed 2026-09-05. It is attributed to Hyadina with high confidence, affects Microsoft Windows (all supported versions with kernel driver loading, maps to 40 MITRE ATT&CK techniques (T1003, T1003.001, T1005), and is covered by 9 detection rules and 40 indicators of compromise.
Key facts for TL-2026-1148
- Threat ID
- TL-2026-1148
- Also known as
- GodDamn ransomware, Hyadina RaaS, Monster/Beast/GodDamn lineage
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-09
- Last reviewed
- 2026-09-05
- Attribution
- Hyadina
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- unspecified broad enterprise targeting
- Target regions
- united states of america, international (excluding historical CIS avoidance under Monster variant)
- Detection rules
- 9
- Indicators of compromise
- 40
- Updates
- 2026-09-05 · 3 updates · revalidated 3× · latest source
Malware and tooling in GodDamn Ransomware (Hyadina)
Malware and tooling: GodDamn, PoisonX, AnyDesk, qTox
Hyadina, a ransomware-as-a-service operation active since March 2022, has rebranded its locker for the third time (Monster -> Beast -> GodDamn), first documented May 21, 2026. GodDamn encrypts victim files (typically the .God8Damn extension or the victim organization's own name) and is deployed alongside PoisonX, a malicious kernel-mode driver (g11.sys) that carries a legitimate Microsoft Hardware Compatibility signature and is used in a BYOVD attack to kill security processes and strip EDR/AV tooling of kernel-level visibility.
How GodDamn Ransomware (Hyadina) works
GodDamn is the latest rebrand of the Hyadina ransomware-as-a-service operation, tracing a lineage from Monster (first observed March 2022, Delphi-written, 32-bit Windows-only, deliberately avoided CIS-region targets) to Beast (June 2024, added Linux/VMware ESXi support, stronger encryption, and multilingual builds including Chinese-language variants) to GodDamn (first documented May 21, 2026). The defining evolution in GodDamn is the integration of PoisonX (file g11.sys, SHA-256 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145d), a malicious kernel driver that its developers succeeded in getting Microsoft to sign via the Windows Hardware Compatibility Program. Because the driver carries a legitimate Microsoft signature, Windows loads it automatically once dropped by an attacker with administrator privileges, making it a textbook Bring-Your-Own-Vulnerable-Driver (BYOVD) defense-evasion tool. PoisonX operates at kernel level to terminate security-related processes, strip endpoint security agents of the rights/hooks they need to function, and tamper with kernel structures to blind AV/EDR tooling — effectively disabling Windows Defender real-time protection and other installed security products. Alongside the driver, the intrusion set deploys a user-mode decoy binary masquerading as "symantec.exe" to further mislead defenders and disable legitimate Symantec/Broadcom protections. Symantec's Threat Hunter Team investigated a real-world intrusion in which the attacker gained initial access, then spent roughly four days conducting reconnaissance, credential harvesting, and lateral movement before deploying the encryptor, ultimately reaching more than ten hosts in the environment. The toolkit is a fairly standard but comprehensive off-the-shelf RaaS affiliate loadout: PsExec for remote command execution and lateral tool transfer, AnyDesk (configured to auto-start as a Windows service) for persistent remote access, Mimikatz for credential dumping, and a large collection of NirSoft utilities (Netpass, WirelessKeyView, CredentialsFileView, MailPassView, ChromePass, PstPassword, MessengerPass, VNCPassView, OperaPassView, WebBrowserPassView, SniffPass, ExtPassword, PasswordFox) to harvest credentials from browsers, VPN clients, Wi-Fi profiles, email clients, and VNC sessions. Netscan was used for internal network discovery, and additional tools (Gmer rootkit scanner, Defender Control, IObit Unlocker) support further defense evasion and unlocking of files held open by other processes prior to encryption. Ransom communication with victims is conducted via email or the qTox encrypted messaging application, consistent with prior Hyadina operations. Notably, the PoisonX driver has also been observed adopted by a separate RaaS operation, The Gentlemen, via a related tool called GentleKiller, indicating the signed driver is being shared or resold within the ransomware-affiliate ecosystem as a commodity BYOVD defense-evasion capability. Victim targeting has expanded from Monster's CIS-avoidance policy to apparent international targeting, with GodDamn's multilingual capability (including Chinese-language support inherited from Beast) suggesting a broad affiliate targeting scope; documented intrusion activity in June 2026 targeted U.S. companies.
MITRE ATT&CK techniques used in TL-2026-1148
Credential Access
T1003 OS Credential Dumping; T1003.001 OS Credential Dumping: LSASS Memory; T1040 Network Sniffing; T1552.001 Unsecured Credentials: Credentials In Files; T1555.003 Credentials from Password Stores: Credentials from Web Browsers; T1555.004 Credentials from Password Stores: Windows Credential Manager; T1558 Steal or Forge Kerberos Tickets
Collection
Defense Evasion
T1014 Rootkit; T1036.005 Match Legitimate Resource Name or Location; T1070 Indicator Removal; T1211 Exploitation for Stealth; T1562 Impair Defenses
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery; T1087 Account Discovery
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares; T1570 Lateral Tool Transfer
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1569.002 System Services: Service Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Command and Control
T1071 Application Layer Protocol; T1219 Remote Access Tools
Initial Access
T1133 External Remote Services
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft
Persistence
T1543.003 Create or Modify System Process: Windows Service; T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions
defense-impairment
T1553.002 Subvert Trust Controls: Code Signing; T1685 Disable or Modify Tools; T1685.001 Disable or Modify Windows Event Log; T1685.005 Clear Windows Event Logs
Resource Development
Affected products and versions in GodDamn Ransomware (Hyadina)
- Microsoft — Windows (all supported versions with kernel driver loading enabled)
Vulnerable versions: Windows systems without HVCI/WDAC driver blocklist enforcement
Fixed in: Windows with Microsoft vulnerable driver blocklist / HVCI enabled and updated - Broadcom/Symantec — Endpoint security products targeted via fake symantec.exe decoy and PoisonX kernel tampering
Vulnerable versions: Endpoint agents lacking kernel-callback tamper protection
Fixed in: N/A - detection/behavioral hardening advised
Remediation for GodDamn Ransomware (Hyadina)
Immediate actions
- Block loading of the PoisonX driver (g11.sys, SHA-256 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145d) via Microsoft's vulnerable driver blocklist (HVCI / WDAC) or third-party BYOVD blocklists
- Hunt for and quarantine all known Hyadina/GodDamn associated tool hashes across endpoints
- Block outbound connections to identified AnyDesk relay IPs used for C2/remote access
- Disable or tightly restrict AnyDesk and other remote-access tooling unless explicitly required by IT, and monitor for AnyDesk installed/configured as a Windows service
- Rotate credentials for any accounts on hosts where NirSoft credential-harvesting tools or Mimikatz artifacts are detected
Workarounds
- Add PoisonX driver hash and filename (g11.sys) to endpoint blocklists pending full HVAC/WDAC rollout
- Restrict driver installation privileges to a minimal set of administrators and require change-control review for new signed drivers
Longer-term hardening
- Enable Windows Defender Application Control (WDAC) / HVCI with Microsoft's recommended driver blocklist to prevent signed-but-vulnerable driver loading
- Deploy EDR with kernel-callback-tampering and driver-load behavioral detection rather than relying solely on AV signature/hash blocking
- Implement network segmentation to constrain lateral movement via PsExec/SMB and reduce blast radius of a single compromised host
- Enforce phishing-resistant MFA and monitor for anomalous credential-harvesting tool execution (NirSoft suite, Mimikatz) via EDR process/behavioral rules
- Establish offline, immutable backups and test ransomware recovery playbooks against a 4-day dwell-time intrusion window
Weaknesses (CWE) in GodDamn Ransomware (Hyadina)
CWE-269, CWE-732, CWE-284, CWE-347
Timeline of GodDamn Ransomware (Hyadina)
- Hyadina first observed deploying the Monster ransomware variant, a Delphi-written, 32-bit Windows-only locker that deliberately avoided CIS-region targets.
- Hyadina rebrands Monster as Beast, adding Linux/VMware ESXi support, enhanced encryption, and multilingual builds including Chinese-language variants.
- A PoisonX.sys reference sample is catalogued by LOLDrivers, carrying a valid Microsoft Windows Hardware Compatibility Publisher signature (certificate valid 2024-10-10 to 2025-10-08).
- GodDamn ransomware, the third Hyadina rebrand, is first documented in the wild, now bundled with the PoisonX signed kernel driver for defense evasion.
- Actor deploys AnyDesk for remote access on the victim network, registering it as two separate Windows auto-start services via a pre-staged PowerShell script (install_ad.ps1).
- Actor stages defense-evasion tooling ahead of the previously-recorded PoisonX deployment: a binary masquerading as symantec.exe and the PoisonX kernel driver (g11.sys).
- Actor begins lateral movement using PsExec and administrative share access (observed against internal host 192.168.0.25), staging the NirSoft/Mimikatz credential-harvesting toolkit.
- Symantec Threat Hunter Team's investigated intrusion begins with initial access to a victim environment (exact vector unreported).
- Attackers deploy NirSoft credential-harvesting suite and Mimikatz, use PsExec and AnyDesk to move laterally, ultimately reaching more than 10 hosts.
- A separate GodDamn intrusion is detected on another network segment, indicating concurrent/parallel affiliate activity beyond the originally investigated incident.
- PoisonX kernel driver (g11.sys) is dropped and loaded using its legitimate Microsoft signature, disabling Windows Defender and other endpoint protection alongside a fake symantec.exe decoy binary.
- GodDamn encryptor (encrypter-windows-gui-x86.exe) is deployed across compromised hosts, roughly 4 days after initial access, encrypting files with the .God8Damn extension or victim-organization-named extensions.
- Broadcom/Symantec publish a Protection Bulletin and blog post detailing the GodDamn rebrand and PoisonX driver abuse.
- Cybersecurity News, The Hacker News, Dark Reading, and GBHackers publish coverage of GodDamn ransomware and PoisonX BYOVD technique, noting US company targeting.
- QuoIntelligence's Weekly Threat Intelligence Snapshot (Week 29 2026) flags the Hyadina/GodDamn/PoisonX rebrand as a cyber highlight, extending public reporting beyond the initial July 8-9 wave.
Update history for TL-2026-1148
- 2026-09-05 — GodDamn Ransomware: Hyadina Group's Rebrand of Beast/Monster with Microsoft-Signed PoisonX Driver BYOVD Evasion: What changed attribution_confidence MEDIUM - HIGH on the Hyadina actor attribution. (The newer report's impact=CRITICAL and nation_state=Russia are noted below but not applied — see revalidation_notes.) New indicators (3) 1 additional Poiso
- 2026-07-16 — GodDamn Ransomware (Beast/Monster Rebrand) Deploys Microsoft-Signed PoisonX Driver to Disable Endpoint Defenses: What changed No severity/exploitability/status escalation — both remain HIGH/ACTIVE/ACTIVE. No new CVEs, CWEs, or IOCs. New MITRE (5) Five additional ATT&CK techniques mapped: T1059.003 (Windows Command Shell), T1547.006 (Kernel Modules and
- 2026-07-10 — GodDamn Ransomware Uses Signed PoisonX Kernel Driver (g11.sys) for Defense Evasion: What changed No field escalations — severity (HIGH), exploitability (ACTIVE), status (ACTIVE), and attribution confidence (MEDIUM) are unchanged. Update is enrichment-only. New indicators (7) 7 new indicators: 6 filename IOCs matching alrea
Sources cited for GodDamn Ransomware (Hyadina)
- GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
- GodDamn Ransomware: Rebrands from Beast
- 'GodDamn' Ransomware Uses BYOVD to Smite US Companies
- GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses
- GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses (Protection Bulletin)
- GodDamn Ransomware Attack Uses PsExec Lateral Movement and NirSoft Toolkit for Credential Theft
- GodDamn Ransomware Uses Signed PoisonX Driver to Disable Defenses
Threats related to GodDamn Ransomware (Hyadina)
- Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR Killers, and Rclone Exfiltration
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation Wave
- Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation
- The Gentlemen Ransomware (RaaS) — Defense Evasion TTPs: Event Log Clearing, Defender Disable & AV Exclusions via PowerShell + Scheduled Tasks (Huntress April/May 2026 IRs)
- N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin Access and Cloudflare Tunnel Persistence
Detection coverage for TL-2026-1148
As of 2026-09-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1148 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1148
1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.