News Room
16
Share
GodDamn Ransomware Employs Microsoft-Signed PoisonX Driver to Neutralize EDR in New Global Campaign
criticalThreat Intelligence

GodDamn Ransomware Employs Microsoft-Signed PoisonX Driver to Neutralize EDR in New Global Campaign

Symantec researchers have identified the GodDamn ransomware using a Microsoft-signed driver called PoisonX to disable EDR tools, marking a critical escalation in kernel-level defense evasion tactics.

₿

Encrygma is selling the entire Full Cyber Weapon Research of GodDamn Ransomware Employs Microsoft-Signed PoisonX Driver to Neutralize EDR in New Global Campaign for ₿ 0.10 BTC. Contact us.

10 July 2026Last updated 20 August 20264 min readSymantec Threat Hunter Team
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
Confirmed
Source:
Symantec Threat Hunter Team
Read Time:
4 min

Executive Summary

Recent telemetry and incident response data from the last 48 hours confirm the emergence of GodDamn, a highly sophisticated ransomware variant within the Hyadina family. Originally documented on July 9, 2026, by the Symantec Threat Hunter Team, this actor has successfully integrated a Microsoft-signed malicious kernel driver, designated PoisonX, to neutralize Endpoint Detection and Response (EDR) solutions. This development represents a dangerous shift from traditional Bring Your Own Vulnerable Driver (BYOVD) attacks toward the deployment of purpose-built malicious drivers that have bypassed Microsoft’s signing process, effectively blinding security perimeters before the encryption phase begins.

Threat Analysis

GodDamn is assessed to be the latest technical iteration of the Beast and Monster ransomware strains, both operated by the cybercriminal collective tracked as Hyadina. The group has historically targeted high-value infrastructure, but recent campaigns show an expanded focus on the healthcare supply chain and industrial manufacturing. GodDamn operators exhibit a high level of operational security, utilizing legitimate remote access tools like AnyDesk and custom credential-harvesting kits to blend in with normal administrative activity. Their dwell time has notably decreased, with full-scale lateral movement and encryption often occurring within 72 hours of initial access. The group leverages double extortion, exfiltrating sensitive intellectual property before deploying the encryptor to maximize pressure on victims.

Technical Details

The core of the GodDamn infection chain is the PoisonX kernel driver (g11.sys). Unlike typical BYOVD attacks that exploit legitimate but vulnerable drivers (like those from old antivirus or hardware vendors), PoisonX is an overtly malicious driver that surprisingly carries a valid Microsoft Windows Hardware Compatibility Publisher signature. When executed via a loader masquerading as a Symantec binary (symantec.exe), PoisonX interacts directly with the kernel to send crafted I/O Control (IOCTL) codes. These codes are specifically designed to terminate the protected processes of major security vendors, including CrowdStrike Falcon and Microsoft Defender. Once the EDR is disabled, the actors deploy a NirSoft-based credential harvester to extract secrets from Windows Credential Manager and browser databases. Lateral movement is then conducted via PsExec, with the attackers spoofing process lineages (running through psexesvc.exe and wininit.exe) to bypass legacy anomaly detection systems.

Attribution Assessment

Encrygma’s analysis aligns with industry reporting that GodDamn is the direct successor to the Beast ransomware. Code analysis reveals an 85% overlap in the Delphi-based encryption module and a identical multi-tiered ransom note structure (README_DECRYPT.txt). Furthermore, the PoisonX driver has also been linked to the 'GentleKiller' toolkit used by The Gentlemen RaaS group, suggesting a centralized development hub or a high-level partnership between Hyadina and the more prolific RaaS franchises. This indicates a maturing cybercrime ecosystem where specialized evasion tools are traded among top-tier ransomware operators.

Implications

The successful use of a signed malicious driver undermines the fundamental trust model of modern endpoint security. If attackers can reliably obtain Microsoft signatures for malware-supporting drivers, the barrier between user-mode protection and kernel-mode total control effectively vanishes. Organizations can no longer rely on 'signed' status as a proxy for safety. Additionally, the integration of these tools into RaaS models like GodDamn means that even lower-skilled affiliates can now perform advanced EDR-killing maneuvers that were previously the sole domain of elite APT groups.

Recommendations

  1. Enhanced Kernel Auditing: Configure advanced auditing (Sysmon Event ID 6) to monitor for the loading of any driver not explicitly on an enterprise-wide allowlist, regardless of signature status.
  2. EDR Tamper Protection: Ensure EDR 'Tamper Protection' and 'Critical Process Protection' features are locked with unique, offline passwords to prevent unauthorized termination attempts.
  3. Phishing-Resistant MFA: Since the initial access vector is often credential compromise, mandate FIDO2-compliant hardware keys for all administrative and developer accounts.
  4. Driver Blocklisting: Immediately update local and cloud-based blocklists to include the hash of the g11.sys driver. Regularly sync with Microsoft’s Vulnerable Driver Blocklist for the latest revocations.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo