Hyadina is a financially motivated ransomware-as-a-service actor associated with the Monster, Beast, and GodDamn ransomware lineage. The group has been active since 2022 and has repeatedly rebranded and refined its tooling, with reported code overlap and operational continuity across these families. Monster was initially a Windows-focused ransomware family, later rebranded as Beast, which expanded to Linux and VMware ESXi support, and then evolved again into GodDamn. Hyadina’s operations emphasize hands-on post-compromise activity before encryption. Observed tradecraft includes use of remote access software for persistent operator access, credential theft with Mimikatz and numerous NirSoft-based utilities, network reconnaissance and scanning, lateral movement with PsExec, service creation for persistence, and disabling built-in protections such as Windows Defender. A notable capability in recent GodDamn intrusions is the use of the PoisonX kernel driver, a malicious driver carrying a valid Microsoft signature, to terminate or blind endpoint security tools at the kernel level before ransomware deployment. The actor has also used masquerading through binaries made to resemble legitimate security software. Victimology indicates a primary focus on organizations in the United States, with reported targeting across healthcare, manufacturing, and education. Hyadina has also been described as avoiding victims in Commonwealth of Independent States countries. The actor’s behavior, tooling choices, and ransomware deployment patterns are consistent with profit-driven cybercrime rather than state-directed activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service group using a signed kernel driver, legitimate remote access software, credential theft tools, and lateral movement utilities to disable security protections and deploy the GodDamn ransomware. The group evolved from earlier variants Beast and Monster to GodDamn.
Named developer attributed with the Monster/Beast/GodDamn ransomware lineage; assessed in the content as financially motivated cybercrime with no state alignment established.
Ransomware-as-a-service developer behind the GodDamn/Beast/Monster ransomware lineage, conducting hands-on intrusions into enterprise Windows networks, using a signed PoisonX kernel driver for defense evasion, credential theft tooling, lateral movement, and file encryption.
Cybercriminal developer/operator attributed with the ransomware lineage Monster → Beast → GodDamn, with observed June 2026 attack activity culminating in deployment of GodDamn ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.