GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver

GodDamn Ransomware (Hyadina) (TL-2026-1148), also tracked as GodDamn ransomware, is a high-severity ransomware operation, first published 2026-07-09 and last reviewed 2026-09-05. It is attributed to Hyadina with high confidence, affects Microsoft Windows (all supported versions with kernel driver loading, maps to 40 MITRE ATT&CK techniques (T1003, T1003.001, T1005), and is covered by 9 detection rules and 40 indicators of compromise.

Key facts for TL-2026-1148

Threat ID
TL-2026-1148
Also known as
GodDamn ransomware, Hyadina RaaS, Monster/Beast/GodDamn lineage
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-09
Last reviewed
2026-09-05
Attribution
Hyadina
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
unspecified broad enterprise targeting
Target regions
united states of america, international (excluding historical CIS avoidance under Monster variant)
Detection rules
9
Indicators of compromise
40
Updates
2026-09-05 · 3 updates · revalidated 3× · latest source

Malware and tooling in GodDamn Ransomware (Hyadina)

Malware and tooling: GodDamn, PoisonX, AnyDesk, qTox

Hyadina, a ransomware-as-a-service operation active since March 2022, has rebranded its locker for the third time (Monster -> Beast -> GodDamn), first documented May 21, 2026. GodDamn encrypts victim files (typically the .God8Damn extension or the victim organization's own name) and is deployed alongside PoisonX, a malicious kernel-mode driver (g11.sys) that carries a legitimate Microsoft Hardware Compatibility signature and is used in a BYOVD attack to kill security processes and strip EDR/AV tooling of kernel-level visibility.

How GodDamn Ransomware (Hyadina) works

GodDamn is the latest rebrand of the Hyadina ransomware-as-a-service operation, tracing a lineage from Monster (first observed March 2022, Delphi-written, 32-bit Windows-only, deliberately avoided CIS-region targets) to Beast (June 2024, added Linux/VMware ESXi support, stronger encryption, and multilingual builds including Chinese-language variants) to GodDamn (first documented May 21, 2026). The defining evolution in GodDamn is the integration of PoisonX (file g11.sys, SHA-256 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145d), a malicious kernel driver that its developers succeeded in getting Microsoft to sign via the Windows Hardware Compatibility Program. Because the driver carries a legitimate Microsoft signature, Windows loads it automatically once dropped by an attacker with administrator privileges, making it a textbook Bring-Your-Own-Vulnerable-Driver (BYOVD) defense-evasion tool. PoisonX operates at kernel level to terminate security-related processes, strip endpoint security agents of the rights/hooks they need to function, and tamper with kernel structures to blind AV/EDR tooling — effectively disabling Windows Defender real-time protection and other installed security products. Alongside the driver, the intrusion set deploys a user-mode decoy binary masquerading as "symantec.exe" to further mislead defenders and disable legitimate Symantec/Broadcom protections. Symantec's Threat Hunter Team investigated a real-world intrusion in which the attacker gained initial access, then spent roughly four days conducting reconnaissance, credential harvesting, and lateral movement before deploying the encryptor, ultimately reaching more than ten hosts in the environment. The toolkit is a fairly standard but comprehensive off-the-shelf RaaS affiliate loadout: PsExec for remote command execution and lateral tool transfer, AnyDesk (configured to auto-start as a Windows service) for persistent remote access, Mimikatz for credential dumping, and a large collection of NirSoft utilities (Netpass, WirelessKeyView, CredentialsFileView, MailPassView, ChromePass, PstPassword, MessengerPass, VNCPassView, OperaPassView, WebBrowserPassView, SniffPass, ExtPassword, PasswordFox) to harvest credentials from browsers, VPN clients, Wi-Fi profiles, email clients, and VNC sessions. Netscan was used for internal network discovery, and additional tools (Gmer rootkit scanner, Defender Control, IObit Unlocker) support further defense evasion and unlocking of files held open by other processes prior to encryption. Ransom communication with victims is conducted via email or the qTox encrypted messaging application, consistent with prior Hyadina operations. Notably, the PoisonX driver has also been observed adopted by a separate RaaS operation, The Gentlemen, via a related tool called GentleKiller, indicating the signed driver is being shared or resold within the ransomware-affiliate ecosystem as a commodity BYOVD defense-evasion capability. Victim targeting has expanded from Monster's CIS-avoidance policy to apparent international targeting, with GodDamn's multilingual capability (including Chinese-language support inherited from Beast) suggesting a broad affiliate targeting scope; documented intrusion activity in June 2026 targeted U.S. companies.

MITRE ATT&CK techniques used in TL-2026-1148

Credential Access

T1003 OS Credential Dumping; T1003.001 OS Credential Dumping: LSASS Memory; T1040 Network Sniffing; T1552.001 Unsecured Credentials: Credentials In Files; T1555.003 Credentials from Password Stores: Credentials from Web Browsers; T1555.004 Credentials from Password Stores: Windows Credential Manager; T1558 Steal or Forge Kerberos Tickets

Collection

T1005 Data from Local System

Defense Evasion

T1014 Rootkit; T1036.005 Match Legitimate Resource Name or Location; T1070 Indicator Removal; T1211 Exploitation for Stealth; T1562 Impair Defenses

Discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery; T1087 Account Discovery

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares; T1570 Lateral Tool Transfer

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1569.002 System Services: Service Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Command and Control

T1071 Application Layer Protocol; T1219 Remote Access Tools

Initial Access

T1133 External Remote Services

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft

Persistence

T1543.003 Create or Modify System Process: Windows Service; T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions

defense-impairment

T1553.002 Subvert Trust Controls: Code Signing; T1685 Disable or Modify Tools; T1685.001 Disable or Modify Windows Event Log; T1685.005 Clear Windows Event Logs

Resource Development

T1588 Obtain Capability

Affected products and versions in GodDamn Ransomware (Hyadina)

  • Microsoft — Windows (all supported versions with kernel driver loading enabled)
    Vulnerable versions: Windows systems without HVCI/WDAC driver blocklist enforcement
    Fixed in: Windows with Microsoft vulnerable driver blocklist / HVCI enabled and updated
  • Broadcom/Symantec — Endpoint security products targeted via fake symantec.exe decoy and PoisonX kernel tampering
    Vulnerable versions: Endpoint agents lacking kernel-callback tamper protection
    Fixed in: N/A - detection/behavioral hardening advised

Remediation for GodDamn Ransomware (Hyadina)

Immediate actions

  • Block loading of the PoisonX driver (g11.sys, SHA-256 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145d) via Microsoft's vulnerable driver blocklist (HVCI / WDAC) or third-party BYOVD blocklists
  • Hunt for and quarantine all known Hyadina/GodDamn associated tool hashes across endpoints
  • Block outbound connections to identified AnyDesk relay IPs used for C2/remote access
  • Disable or tightly restrict AnyDesk and other remote-access tooling unless explicitly required by IT, and monitor for AnyDesk installed/configured as a Windows service
  • Rotate credentials for any accounts on hosts where NirSoft credential-harvesting tools or Mimikatz artifacts are detected

Workarounds

  • Add PoisonX driver hash and filename (g11.sys) to endpoint blocklists pending full HVAC/WDAC rollout
  • Restrict driver installation privileges to a minimal set of administrators and require change-control review for new signed drivers

Longer-term hardening

  • Enable Windows Defender Application Control (WDAC) / HVCI with Microsoft's recommended driver blocklist to prevent signed-but-vulnerable driver loading
  • Deploy EDR with kernel-callback-tampering and driver-load behavioral detection rather than relying solely on AV signature/hash blocking
  • Implement network segmentation to constrain lateral movement via PsExec/SMB and reduce blast radius of a single compromised host
  • Enforce phishing-resistant MFA and monitor for anomalous credential-harvesting tool execution (NirSoft suite, Mimikatz) via EDR process/behavioral rules
  • Establish offline, immutable backups and test ransomware recovery playbooks against a 4-day dwell-time intrusion window

Weaknesses (CWE) in GodDamn Ransomware (Hyadina)

CWE-269, CWE-732, CWE-284, CWE-347

Timeline of GodDamn Ransomware (Hyadina)

  • Hyadina first observed deploying the Monster ransomware variant, a Delphi-written, 32-bit Windows-only locker that deliberately avoided CIS-region targets.
  • Hyadina rebrands Monster as Beast, adding Linux/VMware ESXi support, enhanced encryption, and multilingual builds including Chinese-language variants.
  • A PoisonX.sys reference sample is catalogued by LOLDrivers, carrying a valid Microsoft Windows Hardware Compatibility Publisher signature (certificate valid 2024-10-10 to 2025-10-08).
  • GodDamn ransomware, the third Hyadina rebrand, is first documented in the wild, now bundled with the PoisonX signed kernel driver for defense evasion.
  • Actor deploys AnyDesk for remote access on the victim network, registering it as two separate Windows auto-start services via a pre-staged PowerShell script (install_ad.ps1).
  • Actor stages defense-evasion tooling ahead of the previously-recorded PoisonX deployment: a binary masquerading as symantec.exe and the PoisonX kernel driver (g11.sys).
  • Actor begins lateral movement using PsExec and administrative share access (observed against internal host 192.168.0.25), staging the NirSoft/Mimikatz credential-harvesting toolkit.
  • Symantec Threat Hunter Team's investigated intrusion begins with initial access to a victim environment (exact vector unreported).
  • Attackers deploy NirSoft credential-harvesting suite and Mimikatz, use PsExec and AnyDesk to move laterally, ultimately reaching more than 10 hosts.
  • A separate GodDamn intrusion is detected on another network segment, indicating concurrent/parallel affiliate activity beyond the originally investigated incident.
  • PoisonX kernel driver (g11.sys) is dropped and loaded using its legitimate Microsoft signature, disabling Windows Defender and other endpoint protection alongside a fake symantec.exe decoy binary.
  • GodDamn encryptor (encrypter-windows-gui-x86.exe) is deployed across compromised hosts, roughly 4 days after initial access, encrypting files with the .God8Damn extension or victim-organization-named extensions.
  • Broadcom/Symantec publish a Protection Bulletin and blog post detailing the GodDamn rebrand and PoisonX driver abuse.
  • Cybersecurity News, The Hacker News, Dark Reading, and GBHackers publish coverage of GodDamn ransomware and PoisonX BYOVD technique, noting US company targeting.
  • QuoIntelligence's Weekly Threat Intelligence Snapshot (Week 29 2026) flags the Hyadina/GodDamn/PoisonX rebrand as a cyber highlight, extending public reporting beyond the initial July 8-9 wave.

Update history for TL-2026-1148

Sources cited for GodDamn Ransomware (Hyadina)

Threats related to GodDamn Ransomware (Hyadina)

Detection coverage for TL-2026-1148

As of 2026-09-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1148 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1148

1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats