security-com · Crawled Jul 31, 2026
GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses
13 IoCs 1 Malware
Read original article ↗
AI Summary
The GodDamn ransomware, a rebranded variant of Beast and Monster ransomware, has been used in a recent attack attributed to the threat actor Hyadina. The attackers leveraged AnyDesk for remote access, deployed the malicious PoisonX kernel driver—signed by Microsoft—to disable endpoint defenses, and used a suite of credential-harvesting tools from NirSoft. The attack involved lateral movement via PsExec, deployment of backdoors across multiple hosts, and eventual execution of the ransomware payload after a four-day dwell period. This represents an evolution in defensive evasion tactics, leveraging signed malicious drivers in a BYOVD-style attack.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 13 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 15[.]235[.]230[.]188 | Details → |
| IP | 185[.]229[.]191[.]39 | Details → |
| IP | 141[.]95[.]145[.]210 | Details → |
| IP | 162[.]19[.]171[.]150 | Details → |
| SHA-256 | b29f91a440527fb621d106a2048f6379fff3263c60aeda9c82ff8c1d5ae880a8 | Details → |
| SHA-256 | 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145d | Details → |
| SHA-256 | e097f3b445b63b07afacde8d6a67f0be654dd51e228a3610fb0710a1f7e29a69 | Details → |
| Filename | g11.sys | Details → |
| Filename | symantec.exe | Details → |
| Filename | encrypter-windows-gui-x86.exe | Details → |
| Filename | anydesk.exe | Details → |
| Filename | psexesvc.exe | Details → |
| Filename | netscan.exe | Details → |
MITRE ATT&CK TTPs 72 techniques
T1001.001 Junk Data · Command And Control T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1003.002 Security Account Manager · Credential Access T1018 Remote System Discovery · Discovery T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1033 System Owner/User Discovery · Discovery T1046 Network Service Discovery · Discovery T1048 Exfiltration Over Alternative Protocol · Exfiltration T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · Exfiltration T1053 Scheduled Task/Job · Execution T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.003 Thread Execution Hijacking · Defense Evasion T1057 Process Discovery · Discovery T1059.001 PowerShell · Execution T1070.001 Clear Windows Event Logs · Defense Evasion T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1074 Data Staged · Collection T1074.001 Local Data Staging · Collection T1078 Valid Accounts · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1086 T1086 T1087.001 Local Account · Discovery T1087.002 Domain Account · Discovery T1090.001 Internal Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1098 Account Manipulation · Persistence T1098.001 Additional Cloud Credentials · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1110.003 Password Spraying · Credential Access T1112 Modify Registry · Defense Evasion T1114 Email Collection · Collection T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1212 Exploitation for Credential Access · Credential Access T1222 File and Directory Permissions Modification · Defense Evasion T1222.001 Windows File and Directory Permissions Modification · Defense Evasion T1482 Domain Trust Discovery · Discovery T1484 Domain or Tenant Policy Modification · Defense Evasion T1484.001 Group Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1489 Service Stop · Impact T1490 Inhibit System Recovery · Impact T1537 Transfer Data to Cloud Account · Exfiltration T1543.003 Windows Service · Persistence T1547.001 Registry Run Keys / Startup Folder · Persistence T1558.003 Kerberoasting · Credential Access T1562.001 Disable or Modify Tools · Defense Evasion T1566 Phishing · Initial Access T1569.002 Service Execution · Execution T1570 Lateral Tool Transfer · Lateral Movement T1571 Non-Standard Port · Command And Control T1572 Protocol Tunneling · Command And Control T1573 Encrypted Channel · Command And Control T1573.001 Symmetric Cryptography · Command And Control T1574 Hijack Execution Flow · Persistence T1589 Gather Victim Identity Information · Reconnaissance T1614 System Location Discovery · Discovery