
GodDamn Ransomware Employs PoisonX Signed Driver to Neutralize Enterprise EDR Solutions
Researchers have identified GodDamn, a new ransomware family linked to the Hyadina threat actor. It utilizes a Microsoft-signed kernel driver, PoisonX, to disable security software in BYOVD attacks.
Encrygma is selling the entire Full Cyber Weapon Research of GodDamn Ransomware Employs PoisonX Signed Driver to Neutralize Enterprise EDR Solutions for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Symantec
- Read Time:
- 5 min
Executive Summary
Cybersecurity researchers from Symantec’s Threat Hunter Team have uncovered a new ransomware operation dubbed 'GodDamn.' First spotted in late May and escalating through early July 2026, this threat is notable for its highly effective defense evasion tactics. The ransomware is primarily used to target large enterprise networks, where it systematically disables security protections before initiating data encryption. This report details the evolution of the malware, its tactical execution, and the group behind the campaign.
Threat Analysis
The GodDamn ransomware is assessed to be a direct evolution of the Beast and Monster ransomware families, which have plagued organizations since 2022. The developers, tracked under the moniker 'Hyadina,' have successfully rebranded their operation to incorporate more aggressive persistence and evasion techniques. Unlike previous iterations that relied on basic script-based evasion, GodDamn represents a shift toward kernel-level interference. The group appears to be operating as a highly selective Ransomware-as-a-Service (RaaS) provider, offering their specialized evasion tools to affiliates like 'The Gentlemen' group.
Technical Details
The most significant technical feature of GodDamn is its use of the PoisonX kernel driver, identified as g11.sys. In a classic 'Bring Your Own Vulnerable Driver' (BYOVD) attack, the threat actors deploy this legitimate, Microsoft-signed but malicious driver to gain kernel-mode privileges. Once active, PoisonX is capable of terminating protected processes associated with major Endpoint Detection and Response (EDR) and antivirus solutions. The attack chain typically begins with an unknown initial access vector, followed by the deployment of AnyDesk for persistent remote management. The actors then utilize a customized NirSoft-based toolkit to harvest credentials from web browsers, the Windows Credential Manager, and VNC sessions. A unique user-mode evasion tool, disguised as a legitimate security product (e.g., symantec.exe), coordinates the deployment of the PoisonX driver. After security software is blinded, the final GodDamn encryptor is executed, appending unique extensions to encrypted files and dropping a ransom note that directs victims to the qTox messaging platform for negotiations.
Attribution Assessment
Symantec attributes the development of GodDamn to the threat actor 'Hyadina' with high confidence. This attribution is supported by significant code overlaps between GodDamn and the earlier Beast ransomware. Furthermore, the operational link between the PoisonX driver and the 'GentleKiller' tool used by The Gentlemen RaaS suggests a collaborative ecosystem within the cybercriminal underground. The sophistication of obtaining a Microsoft signature for a malicious driver indicates that Hyadina possesses advanced administrative or social engineering capabilities targeted at software supply chains or signing authorities.
Implications
The emergence of GodDamn highlights a critical vulnerability in the trust model of signed kernel drivers. By successfully abusing the Microsoft signing process, threat actors can bypass the foundational security boundaries of the Windows operating system. This development significantly lowers the barrier for attackers to achieve total system dominance, rendering traditional signature-based and even many behavioral-based security tools ineffective if they are terminated before they can alert.
Recommendations
To mitigate the risk of GodDamn and similar BYOVD threats, organizations should immediately implement driver blocklists, such as the Microsoft-recommended blocklist, to prevent the loading of known vulnerable or malicious drivers. Security teams should monitor for the creation of unauthorized services and the presence of unexpected .sys files in system directories. Additionally, enforcing multi-factor authentication (MFA) on all remote access tools like AnyDesk and restricting the execution of common credential-harvesting tools can disrupt the attack chain prior to the deployment of the ransomware payload.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Operation KillSwitch: Bitdefender Uncovers Escalating Ransomware Tactics in October 2026

Ransomware Surge: August 2026 Hits Record High of 1,073 Global Attacks

