2026-07-11NOTABLESymantec: a driver built malicious from the outset (yet WHCP-signed) defeats code-signing allowlisting to kill EDR before GodDamn encrypts
Hyadina
actor · actor:hyadina
Symantec-tracked ransomware developer behind the Monster (2022) -> Beast -> GodDamn locker lineage; a June 2026 GodDamn intrusion used the Microsoft-signed malicious kernel driver PoisonX for BYOVD-style EDR blinding, AnyDesk for unattended access, PsExec lateral movement and a NirSoft/Mimikatz credential-harvesting kit (Symantec/Broadcom, 2026-07-09).
Coverage
1
first 2026-07-11 → last 2026-07-11
Latest activity
2026-07-11
Symantec: a driver built malicious from the outset (yet WHCP-signed) defeats code-signing allowlisting to…
Peak priority
notable
1 notable
Targets
technology
sectors: technology, public-sector, healthcare
Sources cited
3
3 hosts
Action items (3)
Do-now tasks recorded on the entries about Hyadina, newest first. Check the date before acting on an older one.
- Hunt for a kernel driver-load event immediately followed (same host, short window) by security-product service-stop events or the disappearance of user-mode API hooks, the behavioural signal that survives PoisonX's valid Microsoft signature; do not rely on code-signing allowlisting to catch it.2026-07-11Symantec: a driver built malicious from the outset…
- Alert on remote-access software (AnyDesk) executing from a user profile folder such as Music rather than Program Files, on AnyDesk registered as an auto-start Windows service, and on2026-07-11Symantec: a driver built malicious from the outset…
ad.security.interactive_access=2in an AnyDesk config (suppresses the interactive consent prompt). - Flag2026-07-11Symantec: a driver built malicious from the outset…
Set-MpPreference -DisableRealtimeMonitoring $trueand PsExec lateral movement (psexesvc.exe → services.exe → wininit.exe lineage) with credential-tool staging under a user profile directory.
Defender insights
What each entry about Hyadina tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
uses
Story timeline
Hunting pivots
ATT&CK techniques (9 across 7 tactics)
9 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- PersistenceCreate or Modify System Process: Windows Service · Boot or Logon Autostart Execution: Kernel Modules and Extensions
- Privilege EscalationCreate or Modify System Process: Windows Service · Boot or Logon Autostart Execution: Kernel Modules and Extensions
- Defense ImpairmentSubvert Trust Controls: Code Signing · Disable or Modify Tools
- Credential AccessOS Credential Dumping: LSASS Memory · Credentials from Password Stores: Credentials from Web Browsers
- Lateral MovementRemote Services: SMB/Windows Admin Shares
- Command and ControlRemote Access Tools: Remote Desktop Software
- ImpactData Encrypted for Impact
Persistence TA0003
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
T1547.006Boot or Logon Autostart Execution: Kernel Modules and Extensions×1
Adversaries may modify the kernel to automatically execute programs on system boot. Loadable Kernel Modules (LKMs) are pieces of code that can be loaded and unloaded into the kernel upon demand. They extend the functionality of the kernel without the need to reboot the system. For example, one type of module is the device driver, which allows the kernel to access hardware connected to the system.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
Privilege Escalation TA0004
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
T1547.006Boot or Logon Autostart Execution: Kernel Modules and Extensions×1
Adversaries may modify the kernel to automatically execute programs on system boot. Loadable Kernel Modules (LKMs) are pieces of code that can be loaded and unloaded into the kernel upon demand. They extend the functionality of the kernel without the need to reboot the system. For example, one type of module is the device driver, which allows the kernel to access hardware connected to the system.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
Defense Impairment TA0112
T1553.002Subvert Trust Controls: Code Signing×1
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
Credential Access TA0006
T1003.001OS Credential Dumping: LSASS Memory×1
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
T1555.003Credentials from Password Stores: Credentials from Web Browsers×1
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
Lateral Movement TA0008
T1021.002Remote Services: SMB/Windows Admin Shares×1
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
Command and Control TA0011
T1219.002Remote Access Tools: Remote Desktop Software×1
An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as `VNC`, `Team Viewer`, `AnyDesk`, `ScreenConnect`, `LogMein`, `AmmyyAdmin`, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver · ATT&CK page ↗
Entries about Hyadina (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- PoisonX×1
Where this entity is cited
Source distribution
- infosecurity-magazine.com1 (33%)
- security.com1 (33%)
- thehackernews.com1 (33%)
All cited sources (3)
- infosecurity-magazine.comInfosecurity Magazinehttps://www.infosecurity-magazine.com/news/ransomware-removes-cybersecurity/
- security.comSymantec Threat Hunter Team (Broadcom)https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html