type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [ransomware, loader, cybercrime-group] ยท confidence: medium ยท affected_sectors: [technology, manufacturing, healthcare] ยท au_impact: false
GodDamn Ransomware
GodDamn is a ransomware variant (a rebrand of the Beast/Monster lineage tracked internally as "Hyadina") flagged by Symantec for using the PoisonX kernel driver to disable endpoint defenses before deploying ransomware.
Technical Details
- Defense evasion: Uses PoisonX kernel driver to disable or bypass endpoint detection and response (EDR) tools
- Remote access: Uses Anydesk for hands-on-keyboard remote access
- Credential harvesting: Uses Nirsoft tools for credential theft
- Lineage: Rebrand of Beast/Monster lineage (tracked as "Hyadina" by Symantec) (raw/digests/Cyber-Digest-2026-07-10)
Infection Chain
- Initial access (likely via RDP or phishing)
- PoisonX driver deployed โ EDR/AV disabled
- Credential harvesting via NirSoft tools
- AnyDesk installed for persistent remote access
- Ransomware deployed via hands-on-keyboard
Related Pages
- Gigawiper โ Destructive malware with different objectives
- Redwing Maas โ Malware-as-a-Service model comparison
- Scattered Spider โ Ransomware-focused threat group