Cybersecurity researchers have identified a new ransomware family called GodDamn ransomware, which uses the PoisonX to neutralize security software as part of its defense evasion strategy.
See also: Kasseika ransomware: Uses antivirus driver to disable other antiviruses

According to a report published by Symantec, the ransomware was first observed publicly on May 21, 2026. It is believed to be a redesign of the Beast ransomware, which was an improved version of Monster, a Delphi-based ransomware that appeared in March 2022. Broadcom's cybersecurity division is tracking the developer behind these ransomware families under the alias Hyadina.
In an attack orchestrated by the ransomware operation in early June 2026, the attackers used AnyDesk for remote access and used a NirSoft- before deploying the ransomware. The exact initial means of access is unknown. The credential harvester is designed to extract sensitive data from common web browsers, the Windows Credential Manager, stored domain credentials, VNC sessions, email clients, Wi-Fi profiles, and live network traffic.
Also used in the attack was a user-mode defense evasion tool disguised as a Symantec product (“symantec.exe”) and the PoisonX kernel driver (“g11.sys”) to disable endpoint defenses in a “bring your own vulnerable driver” (BYOVD) attack.
Symantec's Threat Hunters Team noted that the PoisonX driver appears to be a malicious driver that its developers managed to get signed by Microsoft and is now being used by ransomware attackers. PoisonX is one of eight drivers adopted by the operators of the ransomware-as-a-service (RaaS) scheme The Gentlemen in their custom GentleKiller, which is distributed to partners to weaken system defenses before the cryptographer executes.
See also: Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Credentials

Broadcom stressed that vulnerable drivers are the most reliable route for an attacker. Once the attacker gains administrator privileges, they can place a flawed but validly signed driver on the targeted machine, which Windows automatically loads because of its signature.
The most common action taken is to terminate processes belonging to antivirus (AV) or endpoint detection and response (EDR) products, removing the machine's defenses. Some variants are more subtle, stripping the security agent of the privileges it needs to function properly, leaving it running but unable to take action. Others directly interfere with internal kernel files so that the security product no longer receives notifications about what is happening on the machine, effectively rendering it blind.
The attack is also characterized by the use of PsExec to facilitate lateral movement, followed by installing AnyDesk on each of these accessible computers and registering it as a Windows autostart service to survive reboots. On some machines, the entire installation of AnyDesk is done from a PowerShell script prepared on the system disk, indicating the use of a reusable installer to simplify the process.
After completing the AnyDesk installation on each computer, the attackers killed the running AnyDesk process, waited for a while, and then rebooted the machine. By the end of June 2, this deployment sequence had been repeated on at least 10 computers within the targeted organization.
Symantec reported that the GodDamn ransomware was first detected on June 3 on a separate network segment associated with a different organizational unit, causing the files to be renamed with the victim's name as the extension instead of the ".God8Damn" extension used in other attacks carried out by Hyadina.
See also: FortiBleed: Credential theft linked to INC and Lynx Ransomware

According to a report released by CYFIRMA, the ransom note dropped at the end of the attack urges victims to contact them either via email or the encrypted messaging app qTox.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
