Signed Driver Lets Ransomware Blind Defenses

The dangerous part is not the locker itself. It is the trusted Windows driver that lets the attackers shut down security tools before encryption starts, so EDR never gets its usual chance to catch the attack. Symantec says Hyadina used its GodDamn ransomware against U.S. targets in healthcare, manufacturing, and education, along with legitimate RMM software and a Microsoft Hardware Compatibility–signed malicious kernel driver called PoisonX. Once loaded, it killed security processes and stripped user-mode API hooks, which is the control layer many endpoint tools depend on. That flips the normal ransomware assumption. A valid Microsoft signature can still become the weapon, and once that trust is abused, host containment gets much harder.

Part of the PlainSec briefing for 2026-07-11

Sources