
GodDamn Ransomware Employs Microsoft-Signed PoisonX Driver to Neutralize EDR in New Global Campaign
Symantec researchers have identified the GodDamn ransomware using a Microsoft-signed driver called PoisonX to disable EDR tools, marking a critical escalation in kernel-level defense evasion tactics.
Encrygma is selling the entire Full Cyber Weapon Research of GodDamn Ransomware Employs Microsoft-Signed PoisonX Driver to Neutralize EDR in New Global Campaign for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Symantec Threat Hunter Team
- Read Time:
- 4 min
Executive Summary
Recent telemetry and incident response data from the last 48 hours confirm the emergence of GodDamn, a highly sophisticated ransomware variant within the Hyadina family. Originally documented on July 9, 2026, by the Symantec Threat Hunter Team, this actor has successfully integrated a Microsoft-signed malicious kernel driver, designated PoisonX, to neutralize Endpoint Detection and Response (EDR) solutions. This development represents a dangerous shift from traditional Bring Your Own Vulnerable Driver (BYOVD) attacks toward the deployment of purpose-built malicious drivers that have bypassed Microsoft’s signing process, effectively blinding security perimeters before the encryption phase begins.
Threat Analysis
GodDamn is assessed to be the latest technical iteration of the Beast and Monster ransomware strains, both operated by the cybercriminal collective tracked as Hyadina. The group has historically targeted high-value infrastructure, but recent campaigns show an expanded focus on the healthcare supply chain and industrial manufacturing. GodDamn operators exhibit a high level of operational security, utilizing legitimate remote access tools like AnyDesk and custom credential-harvesting kits to blend in with normal administrative activity. Their dwell time has notably decreased, with full-scale lateral movement and encryption often occurring within 72 hours of initial access. The group leverages double extortion, exfiltrating sensitive intellectual property before deploying the encryptor to maximize pressure on victims.
Technical Details
The core of the GodDamn infection chain is the PoisonX kernel driver (g11.sys). Unlike typical BYOVD attacks that exploit legitimate but vulnerable drivers (like those from old antivirus or hardware vendors), PoisonX is an overtly malicious driver that surprisingly carries a valid Microsoft Windows Hardware Compatibility Publisher signature. When executed via a loader masquerading as a Symantec binary (symantec.exe), PoisonX interacts directly with the kernel to send crafted I/O Control (IOCTL) codes. These codes are specifically designed to terminate the protected processes of major security vendors, including CrowdStrike Falcon and Microsoft Defender. Once the EDR is disabled, the actors deploy a NirSoft-based credential harvester to extract secrets from Windows Credential Manager and browser databases. Lateral movement is then conducted via PsExec, with the attackers spoofing process lineages (running through psexesvc.exe and wininit.exe) to bypass legacy anomaly detection systems.
Attribution Assessment
Encrygma’s analysis aligns with industry reporting that GodDamn is the direct successor to the Beast ransomware. Code analysis reveals an 85% overlap in the Delphi-based encryption module and a identical multi-tiered ransom note structure (README_DECRYPT.txt). Furthermore, the PoisonX driver has also been linked to the 'GentleKiller' toolkit used by The Gentlemen RaaS group, suggesting a centralized development hub or a high-level partnership between Hyadina and the more prolific RaaS franchises. This indicates a maturing cybercrime ecosystem where specialized evasion tools are traded among top-tier ransomware operators.
Implications
The successful use of a signed malicious driver undermines the fundamental trust model of modern endpoint security. If attackers can reliably obtain Microsoft signatures for malware-supporting drivers, the barrier between user-mode protection and kernel-mode total control effectively vanishes. Organizations can no longer rely on 'signed' status as a proxy for safety. Additionally, the integration of these tools into RaaS models like GodDamn means that even lower-skilled affiliates can now perform advanced EDR-killing maneuvers that were previously the sole domain of elite APT groups.
Recommendations
- Enhanced Kernel Auditing: Configure advanced auditing (Sysmon Event ID 6) to monitor for the loading of any driver not explicitly on an enterprise-wide allowlist, regardless of signature status.
- EDR Tamper Protection: Ensure EDR 'Tamper Protection' and 'Critical Process Protection' features are locked with unique, offline passwords to prevent unauthorized termination attempts.
- Phishing-Resistant MFA: Since the initial access vector is often credential compromise, mandate FIDO2-compliant hardware keys for all administrative and developer accounts.
- Driver Blocklisting: Immediately update local and cloud-based blocklists to include the hash of the g11.sys driver. Regularly sync with Microsoft’s Vulnerable Driver Blocklist for the latest revocations.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Operation KillSwitch: Bitdefender Uncovers Escalating Ransomware Tactics in October 2026

Aurora and SafePay Ransomware Groups Escalate Double-Extortion Campaigns in October 2026

