Security News

Cybersecurity news aggregator

HIGH Attacks Dark Reading

'GodDamn' Ransomware Uses BYOVD to Smite US Companies

The 'GodDamn' ransomware variant from the Hyadina group employs a Bring Your Own Vulnerable Driver (BYOVD) attack, using a malicious kernel driver named PoisonX that was illegitimately signed with a Microsoft Hardware Compatibility certificate to kill security processes and disable endpoint protection. The attack chain leverages dual-use tools, including legitimate RMM software like AnyDesk and a suite of open-source credential theft utilities, to gain persistence and escalate privileges. No specific software vulnerability, CVSS score, or affected version ranges are detailed in the provided article text.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES THREAT INTELLIGENCE ENDPOINT SECURITY CYBER RISK NEWS 'GodDamn' Ransomware Uses BYOVD to Smite US Companies Microsoft co-signed a malicious kernel driver, and now it's being used to kill security software in ransomware attacks. Nate Nelson,Contributing Writer July 9, 2026 3 Min Read SOURCE: HEMERA TECHNOLOGIES VIA GETTY IMAGES A newly rebranded ransomware outfit is sneaking malware into American organizations using a malicious yet Microsoft-approved driver. Researchers at Symantec recently observed a cyberattack from a group known as "Hyadina." Hyadina is a 4-year-old ransomware-as-a-service (RaaS) operation with a new locker, "GodDamn," an iteration on its previous lockers, "Beast" and "Monster." It typically attacks American organizations, and it also has a distinct distaste for former Soviet countries. Its targets have spanned sectors that include healthcare, manufacturing, education, and wherever else it finds opportunity. In a recent case against an unidentified organization, Hyadina used a smorgasbord of dual-use hacking tools, including legitimate remote monitoring and management (RMM) software, and more than a dozen penetration testing programs. The real kicker, though, was a malicious program with kernel access on Windows, capable of killing any and all processes, including security software. Related:Vidar Infostealer Hammers SMBs via Malvertising Campaign Open Source, Legitimate Tools Lead to Ransomware Researchers couldn't discern Hyadina's choice of social engineering and its initial intrusion tactics. The first sign of bad news came in the form of an unexpected instance of AnyDesk, unconventionally loaded into one infected computer's Music folder, on May 29. AnyDesk is an entirely legitimate software platform, but it's commonly used by attackers instead of old-fashioned shells. A day later, the attacker dropped a binary on a second infected computer, coyly named symantec.exe. Besides breaking the fourth wall, the binary also dropped "PoisonX," a malicious kernel driver which was inexplicably granted a legitimate Microsoft Hardware Compatibility signature. PoisonX killed security-related processes and removed user-mode application programming interface (API) hooks, kneecapping endpoint security tools running on host computers. Next, Hyadina took it up another notch by deploying a toolkit made of 14 different tools. All 14 were open source software (OSS) programs used for different kinds of Windows-based credential theft: browser, email, and instant messenger stealers; Wi-Fi and live network traffic interceptors; and more. All but one of those programs, Mimikatz, came from NirSoft, a free website for Windows utilities. Symantec's Brigid O Gorman laments how "Unfortunately, almost every tool is potentially malicious when in the wrong hands. This is why things like behavioral and adaptive protection are so important — because they block suspicious behavior on the network, even if that behavior emanates from legitimate-seeming tools, rather than simply blocking obviously malicious files or tools." Related:Big Brand Jobs Scam Targets Marketing Pros' Google Accounts By combining the commercial RMM, the signed driver, OSS stealers, and lateral movement through PsExec, Hyadina successfully entrenched itself in its victim's environment and then deployed its ransomware. The Mystery of PoisonX PoisonX, the mysterious signed driver, was published to GitHub on April 7. In a blog post, its author, "oxfemale" described it as a "research tool." Its author releases red team tools at a prolific rate, creating new exploit proofs-of-concept (PoCs), credential stealers, and antivirus killers on a weekly and at times daily basis. On LinkedIn, she claims to be a Russian security researcher specializing in reverse engineering and penetration testing. Dark Reading attempted to contact her to gauge the intent behind her creations, but did not succeed by the time of publication. Symantec has little compunction about labeling PoisonX malware, despite its marketing. It doesn't have any legitimate usage, Gorman says, so in retrospect, "it is easy to say that yes, it shouldn’t have been signed by Microsoft. However, we do not know the steps taken by the attackers to get the driver signed or how they might have tricked Microsoft into doing so." Related:'BusySnake' Infostealer Slithers Into Critical Infrastructure Networks Microsoft maintains a Vulnerable Driver Blocklist for exactly this sort of scenario — blocking known dangerous drivers from loading even if they have a signature, to prevent bring-your-own-vulnerable-driver (BYOVD) attacks. To defend against actors like Hyadina, however, organizations can't necessarily rely on the blocklist alone. "There is a lag of days, more often weeks, between a driver being identified and the blocklist update reaching enterprise endpoints," Gorman notes. "This means that only a subset of known vulnerable drivers is blocklisted at any given time, and unfortunately, attackers often move quicker than the blocklist." About the Author Nate Nelson Contributing Writer Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media. He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify. He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Critical Fortinet Flaws Under Active Attack by Jai Vijayan, Contributing Writer DEC 17, 2025 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES F5 BIG-IP Environment Breached by Nation-State Actor by Alexander Culafi OCT 15, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos, Contributing Writer OCT 03, 2025 Editor's Choice CYBERSECURITY OPERATIONS Why Identity Security Is Your Cyber Career Entry Point byKristina Beek JUN 30, 2026 CYBERATTACKS & DATA BREACHES EdTech Attackers Shift From Schools to Their Software Suppliers byArielle Waldman JUN 25, 2026 CYBERSECURITY OPERATIONS Do CISOs Need a Code of Ethics? byDark Reading Editorial Team JUN 24, 2026 Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article