
criticalThreat Intelligence
GodDamn Ransomware: Hyadina Group Leverages Signed PoisonX Driver to Neutralize Kernel-Level Security Defenses
On July 9, 2026, researchers identified the GodDamn ransomware using a signed PoisonX kernel driver to blind EDR tools, marking a critical escalation in evasion tactics.
₿
Encrygma is selling the entire Full Cyber Weapon Research of GodDamn Ransomware: Hyadina Group Leverages Signed PoisonX Driver to Neutralize Kernel-Level Security Defenses for ₿ 0.10 BTC. Contact us.
10 July 2026Last updated 20 August 20265 min readSymantec Threat Hunter Team
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Symantec Threat Hunter Team
- Read Time:
- 5 min
Executive Summary On July 9, 2026, security researchers identified a significant evolution in the ransomware landscape with the emergence of the 'GodDamn' ransomware family. Developed by the Hyadina threat group, this malware represents a sophisticated rebrand of the previously known 'Beast' and 'Monster' strains. The defining characteristic of this new campaign is the integration of PoisonX, a kernel driver carrying a valid Microsoft signature. This driver is used to systematically disable and blind Endpoint Detection and Response (EDR) solutions, allowing the ransomware to operate with near-total impunity on compromised Windows systems. ## Threat Analysis The Hyadina group, active since early 2022, has demonstrated a consistent trajectory of increasing technical sophistication. GodDamn is their third major iteration, following the Beast ransomware which surfaced in mid-2024. The shift to kernel-level tampering signifies a transition from simple obfuscation to active defense neutralization. By utilizing a signed driver, the group bypasses Windows Driver Signature Enforcement (DSE), a foundational security layer. This tactic is particularly effective because security software often trusts signed drivers by default, allowing the malicious driver to terminate processes and strip permissions from antivirus tools before they can flag the activity. ## Technical Details GodDamn ransomware is primarily distributed through initial access gained via compromised remote access tools like AnyDesk and NirSoft-based credential stealers. Once inside the environment, the PoisonX driver is deployed. This driver functions at Ring 0, allowing it to manipulate the Windows kernel's internal event notifications. Specifically, it tampers with callbacks used by security products to monitor file system activity and process creation. While the security tools appear to be running, they are effectively 'blinded' and do not receive the telemetry necessary to detect the subsequent encryption phase. The ransomware itself shares significant code overlap with the Beast strain but includes updated anti-analysis routines and an optimized encryption engine that avoids systems located in Commonwealth of Independent States (CIS) countries. ## Attribution Assessment Symantec’s Threat Hunter Team attributes GodDamn to the Hyadina group with high confidence. The attribution is based on code similarity, consistent operational infrastructure, and the specific exclusion of CIS-based targets, which is a common hallmark of Eastern European cybercriminal syndicates. The group’s recruitment and advertising patterns on dark web forums like RAMP further support this assessment, showing a preference for experienced affiliates capable of managing complex network environments. ## Implications The use of validly signed kernel drivers in ransomware operations is a critical development for 2026. It highlights a persistent weakness in the driver signing pipeline and the trust models used by modern EDRs. Organizations can no longer rely solely on the presence of a digital signature as a guarantee of safety. As ransomware groups move deeper into the kernel, the timeframe for detection and response shrinks significantly, often leaving defenders with no alerts until the encryption is complete and the ransom note is displayed. ## Recommendations Encrygma recommends the following immediate actions: 1. Implement strict driver blocklists using tools like Microsoft’s recommended blocklist or Windows Defender Application Control (WDAC) to prevent the loading of known malicious or vulnerable signed drivers. 2. Monitor for the unauthorized installation of AnyDesk or similar remote management software, which often serves as the precursor to Hyadina attacks. 3. Enable 'Tamper Protection' features in EDR suites and move toward identity-based micro-segmentation to limit lateral movement. 4. Regularly audit kernel-mode drivers across the enterprise using automated scanning tools to identify anomalies or newly introduced signed components.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News Room


