Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [ransomware, loader, cybercrime-group] ยท confidence: medium ยท affected_sectors: [technology, manufacturing, healthcare] ยท au_impact: false

GodDamn Ransomware

GodDamn is a ransomware variant (a rebrand of the Beast/Monster lineage tracked internally as "Hyadina") flagged by Symantec for using the PoisonX kernel driver to disable endpoint defenses before deploying ransomware.

Technical Details

  • Defense evasion: Uses PoisonX kernel driver to disable or bypass endpoint detection and response (EDR) tools
  • Remote access: Uses Anydesk for hands-on-keyboard remote access
  • Credential harvesting: Uses Nirsoft tools for credential theft
  • Lineage: Rebrand of Beast/Monster lineage (tracked as "Hyadina" by Symantec) (raw/digests/Cyber-Digest-2026-07-10)

Infection Chain

  1. Initial access (likely via RDP or phishing)
  2. PoisonX driver deployed โ†’ EDR/AV disabled
  3. Credential harvesting via NirSoft tools
  4. AnyDesk installed for persistent remote access
  5. Ransomware deployed via hands-on-keyboard

Related Pages