Also known as: user mode, tracked as
GodDamn ransomware represents the third iteration of ransomware developed by Hyadina, following Monster (2022) and Beast (2024). A recent attack in June 2026 demonstrates sophisticated tactics including AnyDesk for remote access, NirSoft-based credential harvesting tools, and the PoisonX kernel driver for defense evasion. PoisonX is a malicious driver signed by Microsoft that terminates security processes at the kernel level. Attackers used PsExec for lateral movement, deployed comprehensive credential theft toolkits comprising 14 different tools, and disabled endpoint defenses before encrypting files. The encrypted files were renamed with victim organization names as extensions. The four-day dwell period allowed attackers to stage payloads and conduct reconnaissance before triggering encryption across at least 10 hosts within the targeted organization.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Hyadina, operating under the alias associated with the GodDamn ransomware, represents a sophisticated threat actor demonstrating advanced tactics in ransomware development and deployment. The group has evolved through iterations including Monster (2022) and Beast (2024), showcasing increasing technical complexity. Their recent attack in June 2026 exhibited the use of AnyDesk for remote access, PoisonX kernel driver for defense evasion, and comprehensive credential harvesting tools, highlighting their capability to disrupt critical operations.
Goals & Targeting
Hyadina's primary goal appears to be financial gain through ransom demands, targeting sectors and organizations that offer high-value assets for encryption. While exact motivations are unclear, their focus on kernel-level persistence and sophisticated tools suggests a strategic approach to maximize data loss and disruption. The targeted sectors include energy and healthcare, which are critical and often have stringent recovery requirements.
Enhanced Description
Hyadina is a notable threat actor known for developing and deploying sophisticated ransomware, with GodDamn representing the latest iteration after earlier versions like Monster (2022) and Beast (2024). The group demonstrated advanced tactics in a June 2026 attack, leveraging AnyDesk for remote access, PoisonX—a malicious kernel driver signed by Microsoft—to terminate security processes, and PsExec for lateral movement. Attackers employed a suite of 14 credential harvesting tools and executed extensive reconnaissance over a four-day dwell period before encrypting files across multiple hosts, renaming them with organizational names as extensions. This campaign underscores Hyadina's ability to orchestrate large-scale ransomware attacks with significant disruption potential.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Hyadina's campaigns are characterized by prolonged dwell periods, sophisticated toolkits, and targeting high-value sectors. Their June 2026 attack highlights the use of multiple techniques to achieve persistence and maximize damage. Notable past operations include the deployment of GodDamn ransomware in large-scale attacks against energy and healthcare organizations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Hyadina's operational capabilities and TTPs due to multiple observed attacks and sophisticated tools. Limited information on exact motivation and targeted countries outside mentioned sectors. No confirmed data on campaigns prior to June 2026.
No campaigns linked yet.
No observed data linked yet.
2
Techniques
44
Tools
0
Campaigns
38
IOCs
0
Observed Data
2
Tactics