Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses

e097f3b445b63b07afacde8d6a67f0be654dd51e228a3610fb0710a1f7e29a69

TLP:CLEAR
Active

SHA-256 Hash

Description

GodDamn ransomware represents the third iteration of ransomware developed by Hyadina, following Monster (2022) and Beast (2024). A recent attack in June 2026 demonstrates sophisticated tactics including AnyDesk for remote access, NirSoft-based credential harvesting tools, and the PoisonX kernel driver for defense evasion. PoisonX is a malicious driver signed by Microsoft that terminates security processes at the kernel level. Attackers used PsExec for lateral movement, deployed comprehensive credential theft toolkits comprising 14 different tools, and disabled endpoint defenses before encrypting files. The encrypted files were renamed with victim organization names as extensions. The four-day dwell period allowed attackers to stage payloads and conduct reconnaissance before triggering encryption across at least 10 hosts within the targeted organization.

Sightings (0)

No sightings recorded yet

Details

Name / Label
GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:07
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of e097f3b445b63b07afacde8d6a67f0be654dd51e228a3610fb0710a1f7e29a69

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.