hacker-news · Crawled Jul 9, 2026

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

2 IoCs
Read original article ↗

AI Summary

The GodDamn ransomware, attributed to the threat actor Hyadina, leverages the Microsoft-signed PoisonX kernel driver (g11.sys) to disable endpoint defenses via a bring your own vulnerable driver (BYOVD) technique. The attack chain includes credential harvesting with NirSoft tools, lateral movement using PsExec, and remote access via AnyDesk, which is deployed through PowerShell scripts and registered as a persistent service. This ransomware is considered a rebrand of Beast, which evolved from Monster, and demonstrates an escalation in defensive evasion capabilities through signed malicious drivers.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename g11.sys Details →
Filename symantec.exe Details →