GodDamn is a Windows ransomware family first publicly observed in 2026 and assessed to be the latest rebrand in the Monster-to-Beast lineage associated with the financially motivated threat actor Hyadina. The family is notable for combining conventional ransomware deployment with extensive pre-encryption intrusion activity, including credential theft, remote access establishment, lateral movement, persistence, and aggressive defense evasion.
A defining characteristic of GodDamn is its use of the PoisonX kernel-mode driver to impair endpoint protections before encryption. PoisonX has been described as a malicious driver carrying a valid Microsoft signature and is used to terminate or blind antivirus and EDR components, remove protections relied on by security tools, and otherwise weaken host defenses at the kernel level. Operators have also used a user-mode tool masquerading as security software to disable protections, reflecting a deliberate effort to neutralize defenses before launching the encryptor.
Observed intrusions linked to GodDamn used AnyDesk for remote access and persistence, NirSoft-based credential-harvesting utilities and Mimikatz for credential theft, network mapping tools for reconnaissance, and PsExec for lateral movement and remote execution across multiple hosts. In documented cases, attackers spent several days expanding access inside enterprise environments before deploying the ransomware broadly. Encrypted files have been renamed either with the .God8Damn extension or with a victim-specific extension derived from the targeted organization, and ransom instructions direct victims to contact the operators through email or encrypted messaging.
The broader lineage has evolved since 2022, when Monster appeared as a Delphi-based ransomware family, later rebranded as Beast in 2024. Beast expanded beyond Windows to include Linux and VMware ESXi targeting, but the supplied facts directly support GodDamn itself as a Windows ransomware family. The campaign profile is consistent with ransomware-as-a-service style operations and has been associated with targeting sectors including healthcare, manufacturing, and education, with no established state alignment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GodDamn is a fresh rebrand of the Beast/Monster ransomware lineage that switches off endpoint defenses before it encrypts.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Perspective The observed behavior aligns with several MITRE ATT&CK techniques, including: ... Windows Management Instrumentation
MITRE ATT&CK Perspective The observed behavior aligns with several MITRE ATT&CK techniques, including: ... Registry Modification
The initial infection vector could not be determined, with the attacker installing AnyDesk on the first victim machine in the Music folder, suggesting a manual action by an attacker with prior access.
MITRE ATT&CK Perspective The observed behavior aligns with several MITRE ATT&CK techniques, including: ... Process Injection
This binary dropped PoisonX, a malicious kernel driver signed by “Microsoft Windows Hardware Compatibility Publisher.” The PoisonX driver works similarly to a signed vulnerable driver in bring-your-own-vulnerable-driver (BYOVD) attacks
AnyDesk is registered as an auto-start Windows service to survive reboots.
After deploying PoisonX for detection evasion, the GodDamn ransomware attacker deployed a comprehensive suite of 14 credentials-harvesting tools comprising Mimikatz and 13 NirSoft tools
The attacker also deployed NetScan, which could be used to map the victim’s network.
Defense Evasion GodDamn employs multiple techniques to avoid detection. These include: Kernel driver abuse Security process termination
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware assessed as a rebrand in the Monster -> Beast -> GodDamn lineage. It disables or blinds endpoint defenses before encryption, using the Microsoft-signed PoisonX kernel driver in a BYOVD-style attack, a fake Symantec user-mode killer, credential theft via NirSoft tools, and lateral movement with PsExec and AnyDesk.
Ransomware deployed in a June 2026 attack; the article describes it as a rebranding of Beast with significant code overlap and as the final payload used after credential collection and defense evasion activity.
A ransomware variant first seen in late May 2026 that encrypts files and appears to be a rebrand of Beast ransomware. It uses the PoisonX malicious driver to disable endpoint defenses and is deployed after credential theft, lateral movement, and network mapping.
A Windows ransomware family that prepares the environment before encryption by harvesting privileged credentials, disabling endpoint security, establishing persistence, and deploying the Microsoft-signed PoisonX kernel driver to interfere with security software before encrypting files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.