Back Darkreading 'GodDamn' Ransomware Uses BYOVD to Smite US Companies
Microsoft signed a malicious kernel driver, and now it's being used to kill security software in ransomware attacks.
A newly rebranded ransomware outfit is sneaking malware into American organizations using a malicious yet Microsoft-approved driver.
Researchers at Symantec recently observed a cyberattack from a group known as "Hyadina." Hyadina is a 4-year-old ransomware-as-a-service (RaaS) operation with a new locker, "GodDamn," an iteration on its lockers, "Beast" and "Monster." It typically attacks American organizations, and it also has a distinct distaste for former Soviet countries . Its targets have spanned sectors that include healthcare, manufacturing, education, and wherever else it finds opportunity.
In a recent case against an unidentified organization, Hyadina used a smorgasbord of dual-use hacking tools, including legitimate remote monitoring and management (RMM) software, and more than a dozen penetration testing programs. The real kicker, though, was a malicious program with kernel access on Windows, capable of killing any and all processes, including security software.
According to Symantec's report , researchers couldn't discern Hyadina's choice of social engineering and its initial intrusion tactics. The first sign of bad news came in the form of an unexpected instance of AnyDesk, unconventionally loaded into one infected computer's Music folder, on May 29. AnyDesk is an entirely legitimate software platform, but it's commonly used by attackers instead of old-fashioned shells.
A day later, the attacker dropped a binary on a second infected computer, coyly named symantec.exe. Besides breaking the fourth wall, the binary also dropped "PoisonX," a malicious kernel driver which was inexplicably granted a legitimate Microsoft Hardware Compatibility signature. PoisonX killed security-related processes and removed user-mode application programming interface (API) hooks, kneecapping endpoint security tools running on host computers.
, Hyadina took it up another notch by deploying a toolkit made of 14 different tools. All 14 were open source software (OSS) programs used for different kinds of Windows-based credential theft: browser, email, and instant messenger stealers; Wi-Fi and live network traffic interceptors; and more. All but one of those programs, Mimikatz , came from NirSoft, a free website for Windows utilities.
Symantec's Brigid O Gorman laments how "Unfortunately, almost every tool is potentially malicious when in the wrong hands. This is why things like behavioral and adaptive protection are so important — because they block suspicious behavior on the network, even if that behavior emanates from legitimate-seeming tools, rather than simply blocking obviously malicious files or tools."
PoisonX, the mysterious signed driver, was published to GitHub on April 7. In a blog post , its author, "oxfemale" described it as a "research tool."
Its author releases red team tools at a prolific rate, creating new exploit proofs-of-concept (PoCs), credential stealers, and antivirus killers on a weekly and at times daily basis. On , she claims to be a Russian security researcher specializing in reverse engineering and penetration testing. Dark Reading attempted to her to gauge the intent behind her creations, but did not succeed by the time of publication.
Symantec has little compunction labeling PoisonX malware, despite its marketing. It doesn't have any legitimate usage, Gorman says, so in retrospect, "it is easy to say that yes, it shouldn’t have been signed by Microsoft. However, we do not know the steps taken by the attackers to get the driver signed or how they might have tricked Microsoft into doing so."
Microsoft maintains a Vulnerable Driver Blocklist for exactly this sort of scenario — blocking known dangerous drivers from loading even if they have a signature, to prevent bring-your-own-vulnerable-driver (BYOVD) attacks. To defend against actors like Hyadina, however, organizations can't necessarily rely on the blocklist alone.
"There is a lag of days, more often weeks, between a driver being identified and the blocklist update reaching enterprise endpoints," Gorman notes. "This means that only a subset of known vulnerable drivers is blocklisted at any given time, and unfortunately, attackers often move quicker than the blocklist."
Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.
He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.
He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.
The State of Cloud Security: The Latest Challenges
The total economic impact™ of Snyk
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Governing the Agent; Identity Security in the Age of Autonomous AI
Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything
Practical Zero Trust Implementation on a Budget in the Age of Mythos
Building a Risk Based Vulnerability Management Program
Threat Hunting That Gets Big Results Despite Small Budgets
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
