HackMyIP
← Back to News
2026-07-09 The Hacker News

GodDamn Ransomware Uses Signed PoisonX Driver to Disable Endpoint Defenses

RansomwareMalwareThreat Intel

Symantec's Threat Hunter Team has identified a new ransomware family, dubbed GodDamn, that leverages a Microsoft-signed kernel driver called PoisonX to neutralize endpoint security products before encryption begins. First observed in the wild on May 21, 2026, GodDamn is assessed to be a rebrand of the Beast ransomware family, itself an evolution of the Delphi-based Monster strain that emerged in March 2022. Broadcom researchers are tracking the developer across all three iterations under the alias Hyadina.

In an early June 2026 intrusion, the operators deployed AnyDesk for persistent remote access and a NirSoft-derived credential harvesting toolkit that targets browser-stored passwords, Windows Credential Manager, cached domain credentials, VNC sessions, email clients, Wi-Fi profiles, and live network traffic. The harvested credentials are then abused to facilitate lateral movement. The attackers also dropped a user-mode defense evasion binary disguised as "symantec.exe," paired with the PoisonX driver ("g11.sys") to terminate AV and EDR processes in a classic bring-your-own-vulnerable-driver (BYOVD) attack. What distinguishes PoisonX is that its developers successfully obtained a Microsoft signature for what is effectively a malicious driver, making it far more dangerous than typical BYOVD payloads. PoisonX is also one of eight drivers adopted by The Gentlemen RaaS operation, which bundles it into its GentleKiller tool used by affiliates to impair system defenses prior to encryption.

After establishing access, the threat actors used PsExec to spread laterally across the network, installing AnyDesk on each reachable host and registering it as an auto-start Windows service to maintain persistence across reboots. The initial access vector remains unconfirmed, but the combination of remote access tooling, credential theft, and signed-driver defense evasion points to a well-resourced and methodical operation. Organizations concerned about exposure should audit driver allowlists, monitor for unsigned or unexpectedly loaded kernel drivers, and verify that no AnyDesk instances are running on hosts where they are not explicitly approved. Admins can quickly check open remote-access ports with the port scanner, and any potentially compromised credentials harvested from browsers or Windows Credential Manager should be evaluated against known exposures using the email breach checker and rotated immediately, with new credentials verified through the password checker.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →