Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Security

GodDamn ransomware blinds EDR with a Microsoft-signed driver

Jesse William McGrawBy Jesse William McGrawJuly 18, 2026No Comments4 Mins Read76 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
GodDamn ransomware blinds EDR with a Microsoft-signed driver, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Symantec’s Threat Hunter Team detailed GodDamn ransomware deploying PoisonX, a kernel driver that carries a genuine Microsoft Windows Hardware Compatibility Publisher signature, to switch off endpoint defenses before encrypting. The driver, shipped as g11.sys, terminates security processes, tampers with kernel callbacks, and strips protections from protected processes. GodDamn is the newest branch of the Hyadina lineage, which ran as Monster in 2022 and Beast in 2024. Operators used AnyDesk, PsExec, and credential tools before encryption. The story is the abuse of a valid signature, not a stolen one.

What is bring-your-own-vulnerable-driver?

Bring-your-own-vulnerable-driver, or BYOVD, is a technique where attackers load a legitimately signed but abusable kernel driver to gain the highest level of access on Windows. Because the driver is signed, Windows trusts it, and from kernel space the attacker can do what user-mode security tools cannot stop, including killing those tools. It has become a standard pre-encryption step for serious ransomware crews. For the wider EDR-evasion trend, see our reporting on how The Gentlemen weaponized a signed driver to kill EDR.

What makes PoisonX notable?

PoisonX is not exploiting a stolen certificate or a forged signature. It carries a valid Microsoft Windows Hardware Compatibility Publisher signature, meaning it passed, at some point, the trust process Windows uses to vet kernel code. Loaded as g11.sys, it terminates processes, tampers with security callbacks, and removes protections from processes that are supposed to be shielded. That combination lets GodDamn operators disable endpoint detection at the kernel level, then encrypt with the defenders effectively deaf and blind.

GODDAMN // KERNEL EDR-KILL ATTACK CHAIN 1. FOOTHOLDAnyDesk, PsExec → 2. CREDENTIALSharvest + spread → 3. LOAD g11.syssigned driver → 4. KILL EDRthen encrypt POISONX DRIVER: WHAT IT DOES FROM THE KERNEL – Carries a valid Microsoft WHCP signature – Terminates security processes – Tampers with kernel security callbacks – Strips protection from protected processes HYADINA LINEAGE MONSTER (2022) → BEAST (2024) → GODDAMN (2026)

How the full attack unfolds

Before the driver ever loads, operators establish a foothold and move laterally using ordinary remote-access and administration tools: AnyDesk for hands-on control, PsExec for remote execution, and credential-harvesting utilities to spread. Only once they have the access they need do they deploy PoisonX to neutralize endpoint defenses, then run the encryptor. The kernel step is the pivot that turns a contained intrusion into a full encryption event, because it removes the tooling that would otherwise catch the ransomware payload.

What defenders can do about signed-driver abuse

Signed-driver abuse is hard to stop with signatures alone, which is the point. Microsoft’s vulnerable-driver blocklist should be enabled and kept current, because it denies known-abusable drivers even when signed. Watch for a new kernel driver loading immediately before security services die, a strong behavioral signal. Restrict who can install drivers, monitor for AnyDesk and PsExec in environments that do not use them, and ensure backups are offline so encryption is recoverable. For control selection, see our guide to business ransomware protection.

Frequently asked questions

What is GodDamn ransomware?

GodDamn is a ransomware family Symantec attributes to the Hyadina lineage, which previously operated as Monster in 2022 and Beast in 2024. It uses a signed kernel driver to disable defenses before encrypting.

How does PoisonX bypass EDR?

PoisonX is a kernel driver that terminates security processes, tampers with kernel callbacks, and strips protections from protected processes, disabling endpoint detection from a level user-mode tools cannot defend.

Why is a Microsoft-signed malicious driver so serious?

A valid Microsoft signature means Windows trusts the driver by default. Detection based on signatures and reputation fails, so defenders must rely on behavior-based signals and driver blocklists instead.

How do I defend against BYOVD attacks?

Enable and update Microsoft’s vulnerable-driver blocklist, restrict driver installation, and alert on any new kernel driver loading just before security services stop. Keep offline backups so encryption remains recoverable.

What tools does GodDamn use before encryption?

Operators use AnyDesk for remote control, PsExec for remote execution, and credential-harvesting tools to move laterally, deploying the PoisonX driver only once they have sufficient access.

Sources and further reading

  • Latest Hacking News: GodDamn ransomware EDR-bypass driver (July 10, 2026)
  • Ransomnews: The Gentlemen weaponised a Kontron driver to kill EDR
  • Ransomnews: Best ransomware protection for business
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleDragonForce: the cartel that absorbed its rivals
Next Article Clover Health discloses social-engineering breach in 8-K
Jesse William McGraw

Jesse William McGraw, also known as GhostExodus, is a former insider threat and threat actor. He became the first person in recent U.S. history to be convicted of corrupting industrial control systems. Today he focuses on threat intelligence, OSINT, and public speaking, using his knowledge to bring awareness to the security risks that organisations and individuals face.

Related Posts

wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030)

July 18, 2026

macOS.Gaslight: malware that prompt-injects your SOC

July 16, 2026

292 fake GitHub repos push a hash-dodging infostealer

July 15, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.