Ransomware & Extortion · Ransomware
Signed Driver Lets Ransomware Blind Defenses The dangerous part is not the locker itself. It is the trusted Windows driver that lets the attackers shut down security tools before encryption starts, so EDR never gets its usual chance to catch the attack.
Symantec says Hyadina used its GodDamn ransomware against U.S. targets in healthcare, manufacturing, and education, along with legitimate RMM software and a Microsoft Hardware Compatibility–signed malicious kernel driver called PoisonX. Once loaded, it killed security processes and stripped user-mode API hooks, which is the control layer many endpoint tools depend on.
That flips the normal ransomware assumption. A valid Microsoft signature can still become the weapon, and once that trust is abused, host containment gets much harder.
3 sources · Jul 10
Timeline Sources Jul 10 Infosecurity Magazine
New Ransomware Exploits Malicious Driver to Remove Security Protection
GodDamn ransomware uses remote desktop application to secretly move around networks and drop the malicious PoisonX kernel driver
original Jul 9 The Hacker News
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
GodDamn ransomware, tied by Symantec to Hyadina's Beast lineage, uses AnyDesk, PsExec, and PoisonX to move and evade defenses.
original Jul 9 Dark Reading
'GodDamn' Ransomware Uses BYOVD to Smite US Companies
Microsoft signed a malicious kernel driver, and now it's being used to kill security software in ransomware attacks.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-07-09
Every edition of this story: Signed Driver Lets Ransomware Blind Defenses
Ransomware & Extortion · Ransomware
Signed Driver Lets Ransomware Blind Defenses The dangerous part is not the locker itself. It is the trusted Windows driver that lets the attackers shut down security tools before encryption starts, so EDR never gets its usual chance to catch the attack.
Symantec says Hyadina used its GodDamn ransomware against U.S. targets in healthcare, manufacturing, and education, along with legitimate RMM software and a Microsoft Hardware Compatibility–signed malicious kernel driver called PoisonX. Once loaded, it killed security processes and stripped user-mode API hooks, which is the control layer many endpoint tools depend on.
That flips the normal ransomware assumption. A valid Microsoft signature can still become the weapon, and once that trust is abused, host containment gets much harder.
3 sources · Jul 10
Timeline Sources Jul 10 Infosecurity Magazine
New Ransomware Exploits Malicious Driver to Remove Security Protection
GodDamn ransomware uses remote desktop application to secretly move around networks and drop the malicious PoisonX kernel driver
original Jul 9 The Hacker News
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
GodDamn ransomware, tied by Symantec to Hyadina's Beast lineage, uses AnyDesk, PsExec, and PoisonX to move and evade defenses.
original Jul 9 Dark Reading
'GodDamn' Ransomware Uses BYOVD to Smite US Companies
Microsoft signed a malicious kernel driver, and now it's being used to kill security software in ransomware attacks.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-07-09
Every edition of this story: Signed Driver Lets Ransomware Blind Defenses