Hyadina is a ransomware threat actor and developer associated with the Monster, Beast, and GodDamn ransomware lineage. The group has been active since at least March 2022 and is assessed to have operated its ransomware as a service, with successive rebrands and iterative technical improvements across variants. Monster was an early Windows-focused strain reportedly written in Delphi and initially targeting 32-bit systems, while later Beast and GodDamn variants expanded capabilities to Linux and VMware ESXi environments and introduced broader language support and improved encryption routines. Hyadina’s operations are characterized by hands-on post-compromise activity, credential theft, lateral movement, persistence through remote administration software, and increasingly sophisticated defense evasion. Observed intrusions have used AnyDesk for remote access and persistence, PsExec for lateral movement, network discovery tooling, Mimikatz, and numerous NirSoft credential-recovery utilities to harvest credentials from browsers, Windows credential stores, email clients, VNC sessions, and wireless profiles. The group typically spends multiple days inside victim environments before encryption, indicating a deliberate intrusion model focused on privilege escalation, network expansion, and operational preparation. A notable evolution in Hyadina tradecraft is the use of the PoisonX kernel driver to disable or weaken endpoint protections before ransomware deployment. PoisonX has been described as a malicious driver carrying a valid Microsoft signature and capable of terminating security processes and removing protective hooks at the kernel level. This reflects a significant escalation in defensive evasion compared with earlier Hyadina activity, which had already incorporated tools to disable security products and unlock files for encryption. GodDamn is widely assessed as the latest rebrand of Beast, which itself followed Monster, with significant code and tradecraft overlap across the family. Hyadina-linked ransomware deployments have also shown customization of encrypted file extensions to match victim organizations in some cases, suggesting tailored operations intended to improve stealth or branding pressure during extortion. The group has been reported to avoid targeting organizations in Commonwealth of Independent States countries. Reported victim sectors include healthcare, manufacturing, and education, with a particular focus on organizations in the United States. Known aliases and associated names in this lineage include Monster, Beast, and GodDamn as Hyadina-developed ransomware families rather than separate actor identities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tracked as the developer behind the Monster, Beast, and GodDamn ransomware families. In the observed intrusion, actors leveraging these Hyadina ransomware families used PoisonX for defense evasion, AnyDesk for remote access and persistence, Mimikatz and NirSoft tools for credential harvesting, NetScan for network mapping, and PsExec for lateral movement before deploying ransomware.
Operates the GodDamn ransomware and is described as conducting mature ransomware intrusions that obtain privileged credentials, disable endpoint security using a Microsoft-signed kernel driver, establish persistence, move laterally, and then encrypt victim systems.
Develops and operates the Beast/Monster/GodDamn ransomware family. In this campaign, the actor uses AnyDesk for remote access, credential-stealing toolkits, and the Microsoft-signed PoisonX kernel driver to disable endpoint security via a BYOVD-style defense evasion technique before deploying ransomware. The actor also customizes file extensions based on the victim organization to improve stealth.
Developer/operator behind the Monster → Beast → GodDamn ransomware lineage, refining the ransomware family across multiple rebrands and using credential theft, lateral movement, remote access tooling, and a malicious signed kernel driver to disable defenses before encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.