GodDamn ransomware PoisonX BYOVD activity
Malware Activity
Summary
Hide ▲
Show ▼
GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver to disable endpoint defenses before encrypting files. Public reporting places the latest variant in May 2026 and ties it to an early June 2026 intrusion in which operators used PsExec for lateral movement and repeated the deployment across at least 10 hosts. The activity shows a reusable ransomware workflow that reduces detection, expands access, and ends with file encryption and ransom notes.
Related Happenings
Qilin (aka Agenda) ransomware deployment after PAN-OS exploitation
Malware Activity
H score40
First: 21.07.2026 17:04
Last: 21.07.2026 17:04
Sources 1
About this happening:
Qilin (aka Agenda) ransomware was deployed across multiple June 2026 intrusions after attackers exploited CVE-2026-0257 in Palo Alto Networks PAN-OS to gain initia...
Qilin (aka Agenda) ransomware deployment after PAN-OS exploitation
Malware ActivityAbout this happening: Qilin (aka Agenda) ransomware was deployed across multiple June 2026 intrusions after attackers exploited CVE-2026-0257 in Palo Alto Networks PAN-OS to gain initia...
HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware Activity
H score15
First: 20.07.2026 15:30
Last: 20.07.2026 15:30
Sources 1
About this happening:
HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...
HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware ActivityAbout this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...
IT services firm in South Asia hit by ransomware attack
Incident
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
IT services firm in South Asia hit by ransomware attack
IncidentAbout this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
Major U.S. services company hit by ransomware attack linked to DragonForce
Incident
H score38
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
About this happening:
A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Major U.S. services company hit by ransomware attack linked to DragonForce
IncidentAbout this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
The Gentlemen ransomware group’s 90/10 RaaS model and rapid victim growth
Threat Actor Meta
H score26
First: 10.06.2026 17:03
Last: 10.06.2026 17:03
Sources 1
About this happening:
The Gentlemen ransomware group has become a high-volume RaaS operation, using a 90/10 affiliate split to attract operators and expand its reach. The group now ranks as...
The Gentlemen ransomware group’s 90/10 RaaS model and rapid victim growth
Threat Actor MetaAbout this happening: The Gentlemen ransomware group has become a high-volume RaaS operation, using a 90/10 affiliate split to attract operators and expand its reach. The group now ranks as...
Timeline
-
09.07.2026 13:43 1 articles · 13d ago
GodDamn ransomware is first publicly spotted
Initial DisclosureGodDamn ransomware is first publicly spotted in the wild on May 21, 2026 and is assessed as a rebrand of Beast ransomware, which traces back to Monster.
Show sources
- GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses — thehackernews.com — 09.07.2026 13:43
-
09.07.2026 13:43 3 articles · 13d ago
GodDamn operators deploy AnyDesk, PsExec, and PoisonX across targeted hosts
Technical Analysis UpdateDuring an early June 2026 intrusion, the operators use AnyDesk for remote access, PsExec for lateral movement, a NirSoft-based credential harvester, and the PoisonX kernel driver alongside a fake symantec.exe component to disable endpoint defenses; by the end of June 2, the deployment sequence has been repeated across at least 10 hosts within the targeted organization.
Show sources
- GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses — thehackernews.com — 09.07.2026 13:43
- GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses — thehackernews.com — 09.07.2026 13:43
- New Ransomware Exploits Malicious Driver to Remove Cybersecurity Protections — www.infosecurity-magazine.com — 10.07.2026 16:00
-
09.07.2026 13:43 1 articles · 13d ago
GodDamn ransomware is detected on a separate network segment
Victim Impact UpdateGodDamn ransomware is first detected on June 3, 2026 on a separate network segment associated with a distinct organizational unit, and the files on those systems are renamed with the victim's name as the extension instead of .God8Damn.
Show sources
- GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses — thehackernews.com — 09.07.2026 13:43