Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors hyadina

Also known as: user mode, tracked as

Description

GodDamn ransomware represents the third iteration of ransomware developed by Hyadina, following Monster (2022) and Beast (2024). A recent attack in June 2026 demonstrates sophisticated tactics including AnyDesk for remote access, NirSoft-based credential harvesting tools, and the PoisonX kernel driver for defense evasion. PoisonX is a malicious driver signed by Microsoft that terminates security processes at the kernel level. Attackers used PsExec for lateral movement, deployed comprehensive credential theft toolkits comprising 14 different tools, and disabled endpoint defenses before encrypting files. The encrypted files were renamed with victim organization names as extensions. The four-day dwell period allowed attackers to stage payloads and conduct reconnaissance before triggering encryption across at least 10 hosts within the targeted organization.

Goals & Targeting

Targeted Sectors

Defense
Healthcare
Financial services
Manufacturing
Education
Government
Critical infrastructure
Energy
Food agriculture

Targeted Countries / Regions

US

AI Analysis

· 1 week ago

Executive Summary

Hyadina, operating under the alias associated with the GodDamn ransomware, represents a sophisticated threat actor demonstrating advanced tactics in ransomware development and deployment. The group has evolved through iterations including Monster (2022) and Beast (2024), showcasing increasing technical complexity. Their recent attack in June 2026 exhibited the use of AnyDesk for remote access, PoisonX kernel driver for defense evasion, and comprehensive credential harvesting tools, highlighting their capability to disrupt critical operations.

Goals & Targeting

Hyadina's primary goal appears to be financial gain through ransom demands, targeting sectors and organizations that offer high-value assets for encryption. While exact motivations are unclear, their focus on kernel-level persistence and sophisticated tools suggests a strategic approach to maximize data loss and disruption. The targeted sectors include energy and healthcare, which are critical and often have stringent recovery requirements.

Enhanced Description

Hyadina is a notable threat actor known for developing and deploying sophisticated ransomware, with GodDamn representing the latest iteration after earlier versions like Monster (2022) and Beast (2024). The group demonstrated advanced tactics in a June 2026 attack, leveraging AnyDesk for remote access, PoisonX—a malicious kernel driver signed by Microsoft—to terminate security processes, and PsExec for lateral movement. Attackers employed a suite of 14 credential harvesting tools and executed extensive reconnaissance over a four-day dwell period before encrypting files across multiple hosts, renaming them with organizational names as extensions. This campaign underscores Hyadina's ability to orchestrate large-scale ransomware attacks with significant disruption potential.

Key Capabilities

  • Developing advanced ransomware iterations
  • Using AnyDesk for remote access
  • Employing the PoisonX kernel driver for defense evasion
  • Deploying comprehensive credential theft toolkits
  • Leveraging PsExec for lateral movement
  • Spear-phishing with malicious Office documents
  • Kernel-level persistence techniques

MITRE ATT&CK Tactics

Credential Access
Execution
Lateral Movement
Defense Evasion
Collection

ATT&CK Techniques

T1070.003
T1082
T1566.001
T1093
T1566.004

Software / Tooling

AnyDesk
PoisonX Kernel Driver
PsExec
NirSoft tools
Custom credential theft toolkit

Campaigns & Victims

Hyadina's campaigns are characterized by prolonged dwell periods, sophisticated toolkits, and targeting high-value sectors. Their June 2026 attack highlights the use of multiple techniques to achieve persistence and maximize damage. Notable past operations include the deployment of GodDamn ransomware in large-scale attacks against energy and healthcare organizations.

IOC Patterns

  • Remotefile dropped with AnyDesk remote access tool
  • Malicious Microsoft-signed kernel driver activity (PoisonX)
  • Lateral movement using PsExec over command-line interface
  • Spear-phishing emails with malicious Office documents
  • Encrypted files renamed with victim organization names as extensions

Recommended Actions

  • Implement network monitoring for AnyDesk-related processes
  • Enhance kernel-level security to detect malicious drivers
  • Conduct regular backups and ensure air-gapped storage
  • Enforce multi-factor authentication (MFA) for critical systems
  • Monitor for异常 process termination patterns indicative of PoisonX

Suggested Tags

APT
Ransomware
Critical Infrastructure
Energy Sector
HealthcareSector

Confidence Assessment

High confidence in Hyadina's operational capabilities and TTPs due to multiple observed attacks and sophisticated tools. Limited information on exact motivation and targeted countries outside mentioned sectors. No confirmed data on campaigns prior to June 2026.

ATT&CK Techniques

Command & Control
1 technique
Stealth
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.smarttech247.com — Cited by web research for: Mimikatz
  2. pmc.ncbi.nlm.nih.gov — Cited by web research for: PLAY
  3. www.security.com — Cited by web research for: PowerShell
  4. pmc.ncbi.nlm.nih.gov — Cited by web research for: Financial Services

Intel Summary

2

Techniques

44

Tools

0

Campaigns

38

IOCs

0

Observed Data

2

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
Data Exfiltration
APT
Energy Sector
HealthcareSector

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.