Cybersecurity analysts have identified a new variant of ransomware known as GodDamn, which utilizes the PoisonX kernel driver to circumvent security measures during its attacks. This advanced tactic is part of a broader strategy for evading detection in network environments.
The recent findings, highlighted in a Symantec Threat Hunter Team report, indicate that GodDamn was first reported on May 21, 2026. This ransomware is recognized as a rebranding of the Beast ransomware, which itself evolved from the Monster variant, a Delphi-based malware that emerged in March 2022. The company Broadcom is currently tracing the origins of these ransomware variants to the operators identified as Hyadina.
In an attack associated with GodDamn in early June 2026, cybercriminals reportedly employed AnyDesk for remote system access alongside a NirSoft-based credential harvesting toolkit. Although the specific point of initial access remains unclear, the credential harvesting tool is designed to extract sensitive information from a variety of sources, including web browsers, email clients, and Wi-Fi profiles, significantly enhancing the attackers’ foothold in the environment.
Additionally, the attack involved a user-mode defense evasion tool disguised as a Symantec product, named “symantec.exe”, in conjunction with the PoisonX kernel driver (identified as “g11.sys”). This method facilitated a bring your own vulnerable driver (BYOVD) exploit, allowing attackers to disable endpoint security mechanisms effectively.
Symantec experts highlighted that the PoisonX driver is particularly noteworthy as it appears to be a malicious driver that was successfully signed by Microsoft, which has now been co-opted by ransomware groups. The Threat Hunter Team noted that this type of driver represents a serious escalation in the sophistication of defensive evasion techniques utilized by cybercriminal organizations.
PoisonX is among several drivers adopted by the operators behind the Gentlemen ransomware-as-a-service (RaaS) scheme, employed in their GentleKiller tool to compromise targeted systems prior to initiating encryption processes.
Broadcom has pointed out that vulnerable drivers present a reliable access point for attackers. Once the adversaries have obtained administrative privileges, they can install a compromised but validly signed driver, leading to the automatic loading of the driver by Windows. This technique often results in the disabling of antivirus and endpoint detection and response solutions, either by terminating processes or manipulating internal records to prevent alerts.
Furthermore, the attack sequence observed included the use of PsExec for lateral movement. Following this, attackers configured AnyDesk on each target host, ensuring it is registered as an auto-start service, allowing it to persist through system reboots. Some systems exhibited signs that the AnyDesk installation was facilitated through a pre-staged PowerShell script, indicating a systematic approach to streamline the deployment process.
On June 3, the GodDamn ransomware was detected in a distinct network segment linked to a different organizational unit. Notably, the files were renamed with the victim’s name as the extension rather than the “.God8Damn” extension commonly associated with previous attacks by Hyadina, illustrating a potentially evolving tactic aimed at further personalization of the attack.
A ransom note found at the conclusion of the intrusion instructed victims to contact the attackers via email or the qTox encrypted messaging application, outlining the typical demands associated with ransomware incidents.
The emergence of GodDamn, particularly its use of the PoisonX driver, signifies a marked enhancement in the operational capabilities of this ransomware group, indicating ongoing investment in their tools and techniques.