{"id":1681,"date":"2026-07-09T14:40:07","date_gmt":"2026-07-09T14:40:07","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1681"},"modified":"2026-07-09T14:40:07","modified_gmt":"2026-07-09T14:40:07","slug":"goddamn-ransomware-uses-poisonx-driver-to-disable-endpoint-defenses","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1681","title":{"rendered":"GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 09, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Endpoint Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEge_nKJNwSt3ZRkzfZ2qH61_1WFg5hyphenhyphenMSrC3-JM4AOXRKO-IVsJXFNiM926QnG25eTply3DRF57t61wi5Ucy4yxald1RpH1TRbItw83RqQ-K6UM670vpR76-kBl2xcntaDE7lxxNwurseG5iRM4sMhYK8Npb9COGNM_XjbwBLthnJjBfwqV7m96VKOnWb3Q\/s1700-e365\/endpoint-ransomware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have flagged a new ransomware family called <strong>GodDamn<\/strong> that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy.<\/p>\n<p>According to a <a href=\"https:\/\/www.security.com\/threat-intelligence\/goddamn-ransomware-beast-rebrand\" target=\"_blank\">new report<\/a> published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It&#8217;s assessed to be a rebrand of the <a href=\"https:\/\/securelist.com\/ransomware-updates-1-day-exploits\/107291\/\" target=\"_blank\">Beast<\/a> ransomware, which, in turn, was an enhanced version of <a href=\"https:\/\/cyberint.com\/blog\/research\/the-nature-of-the-beast-ransomware\/\" target=\"_blank\">Monster<\/a>, a Delphi-based ransomware that surfaced in March 2022. Broadcom&#8217;s cybersecurity arm is tracing the developer behind these ransomware families under the moniker Hyadina.<\/p>\n<p>In one attack orchestrated by the ransomware operation in early June 2026, the threat actors are said to have leveraged AnyDesk for remote access and used a <a href=\"https:\/\/knowledge.broadcom.com\/external\/article\/445443\/detection-and-blocking-of-nirsoft-tool-a.html\" target=\"_blank\">NirSoft-based credential harvesting toolkit<\/a> before deploying the ransomware. The exact initial access vector is unknown. The credential harvester is designed to extract sensitive data from common web browsers, Windows Credential Manager, cached domain credentials, VNC sessions, email clients, Wi-Fi profiles, and live network traffic.<\/p>\n<p>Also put to use in the attack is a user-mode defense evasion tool that&#8217;s dressed as a Symantec product (\u00absymantec.exe\u00bb) and the PoisonX kernel driver (\u00abg11.sys\u00bb) to disable endpoint defenses in what&#8217;s called a bring your own vulnerable driver (BYOVD) attack.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abHowever, the PoisonX driver seems to be slightly more unusual, in that it appears to be a malicious driver that its developers succeeded in getting signed by Microsoft, and it is now being used by ransomware attackers,\u00bb the Symantec Threat Hunter Team said in a report shared with The Hacker News.<\/p>\n<p>It&#8217;s worth noting that PoisonX is one of the eight drivers adopted by the operators of The Gentlemen ransomware-as-a-service (RaaS) scheme in its custom <a href=\"https:\/\/thehackernews.com\/2026\/06\/the-gentlemen-raas-uses-gentlekiller.html\" target=\"_blank\">GentleKiller tool that it hands out to affiliates for impairing system defenses prior to executing the encryptor.<\/p>\n<p>\u00abVulnerable drivers are the attacker&#8217;s most reliable route in,\u00bb Broadcom <a href=\"https:\/\/www.security.com\/threat-intelligence\/byovd-vulnerable-drivers\" target=\"_blank\">noted<\/a> last month. \u00abThe attacker, having gained administrator privileges, can drop a flawed but validly signed driver onto the target machine. Because the driver is signed, Windows loads it automatically.\u00bb<\/p>\n<p>\u00abThe most common action is to kill the processes belonging to antivirus (AV) or endpoint detection and response (EDR) products, stripping the machine of its defenses. Some variants are more subtle. Attackers may strip the security agent of the rights it needs to function correctly, leaving it running but unable to act. Others tamper directly with the kernel&#8217;s internal records so that the security product no longer receives notifications about what is happening on the machine, effectively making it blind.\u00bb<\/p>\n<p>The attack is also characterized by the use of PsExec to facilitate lateral movement, followed by setting up AnyDesk on each of those reachable hosts and registering it as an auto-start Windows service to survive reboots. On some machines, the entire AnyDesk setup is handled by a PowerShell script pre-staged on the system drive, suggesting the use of a reusable installer to streamline the process.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqmM4NpfZsx4cw-HrXQlCjZQmrF8bYnmB23AmpOPi16kPNB9lvICjpdYEclxJwyQ9OE8GgzQ8aOEI68tRuxNqov0MHz2Sq8xEPiYWM3Js6FM5t2nm2JHWodmR7qVSot14ZtWVqQRQ6B88OnMaVxCPwRG7xGPoIIZxF6QAhWVhMkQfs11NjyNtHsGEUH4_q\/s728-e100\/sygnia-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abAfter completing the AnyDesk setup on each host, the attackers terminated the running AnyDesk process, waited briefly, then rebooted the machine,\u00bb Symantec said. \u00abBy the end of June 2, this deployment sequence had been repeated across at least 10 hosts within the targeted organization.\u00bb<\/p>\n<p>The cybersecurity company said GodDamn ransomware was first detected on June 3 on a separate network segment associated with a distinct organizational unit, causing the files to be renamed with the victim&#8217;s name as the extension instead of the \u00ab.God8Damn\u00bb extension used in other attacks carried out by Hyadina.<\/p>\n<p>According to a report <a href=\"https:\/\/www.cyfirma.com\/news\/weekly-intelligence-report-19-jun-2026\/\" target=\"_blank\">released<\/a> by CYFIRMA, the ransom note dropped at the end of the intrusion urges victims to contact them either via email or the qTox encrypted messaging\u00a0app.<\/p>\n<p>\u00abGodDamn&#8217;s use of the relatively newly discovered PoisonX malicious driver component represents an escalation in defensive evasion capability by this group, indicating that Hyadina is continuing to actively develop its ransomware and its capabilities,\u00bb the cybersecurity company concluded.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 09, 2026Malware \/ Endpoint Security Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1682,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[899,772,865,2423,2443,2444,93],"class_list":["post-1681","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-defenses","tag-disable","tag-driver","tag-endpoint","tag-goddamn","tag-poisonx","tag-ransomware"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1681","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1681"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1681\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1682"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1681"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1681"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1681"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}