Find notable cyber news and cases, enriched with sources, timelines, and signals.

GodDamn ransomware PoisonX BYOVD activity

Malware Activity
First reported
Last updated
Happening score
H score 14
2 unique sources, 2 articles

Summary

Hide ▲

GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver to disable endpoint defenses before encrypting files. Public reporting places the latest variant in May 2026 and ties it to an early June 2026 intrusion in which operators used PsExec for lateral movement and repeated the deployment across at least 10 hosts. The activity shows a reusable ransomware workflow that reduces detection, expands access, and ends with file encryption and ransom notes.

Related Happenings

Qilin (aka Agenda) ransomware deployment after PAN-OS exploitation

Malware Activity
H score40 First: 21.07.2026 17:04 Last: 21.07.2026 17:04 Sources 1

About this happening: Qilin (aka Agenda) ransomware was deployed across multiple June 2026 intrusions after attackers exploited CVE-2026-0257 in Palo Alto Networks PAN-OS to gain initia...

HollowGraph Windows malware uses Microsoft 365 calendars for covert C2

Malware Activity
H score15 First: 20.07.2026 15:30 Last: 20.07.2026 15:30 Sources 1

About this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...

IT services firm in South Asia hit by ransomware attack

Incident
H score31 First: 16.07.2026 13:00 Last: 16.07.2026 13:00 Sources 1

About this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...

Major U.S. services company hit by ransomware attack linked to DragonForce

Incident
H score38 First: 16.06.2026 13:18 Last: 16.06.2026 13:18 Sources 1

About this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...

The Gentlemen ransomware group’s 90/10 RaaS model and rapid victim growth

Threat Actor Meta
H score26 First: 10.06.2026 17:03 Last: 10.06.2026 17:03 Sources 1

About this happening: The Gentlemen ransomware group has become a high-volume RaaS operation, using a 90/10 affiliate split to attract operators and expand its reach. The group now ranks as...

Timeline

  1. 09.07.2026 13:43 3 articles · 13d ago

    GodDamn operators deploy AnyDesk, PsExec, and PoisonX across targeted hosts

    Technical Analysis Update

    During an early June 2026 intrusion, the operators use AnyDesk for remote access, PsExec for lateral movement, a NirSoft-based credential harvester, and the PoisonX kernel driver alongside a fake symantec.exe component to disable endpoint defenses; by the end of June 2, the deployment sequence has been repeated across at least 10 hosts within the targeted organization.

    Show sources
  2. 09.07.2026 13:43 1 articles · 13d ago

    GodDamn ransomware is detected on a separate network segment

    Victim Impact Update

    GodDamn ransomware is first detected on June 3, 2026 on a separate network segment associated with a distinct organizational unit, and the files on those systems are renamed with the victim's name as the extension instead of .God8Damn.

    Show sources