Beast is a ransomware family associated with the threat actor tracked as Hyadina and is part of a lineage that evolved from Monster and later into GodDamn. The family has been operated as a ransomware-as-a-service offering and has targeted organizations across multiple sectors, including healthcare, manufacturing, and education, while reportedly avoiding victims in CIS countries. Beast emerged as a rebrand of Monster and represented an expansion of the family’s capabilities, including support for Linux and VMware ESXi in addition to Windows.
Beast operations have involved pre-encryption intrusion activity rather than immediate detonation. Reported tradecraft includes remote access through AnyDesk, credential theft using NirSoft utilities and Mimikatz, network reconnaissance and scanning, lateral movement with PsExec, and efforts to disable or weaken security controls before encryption. Across this family lineage, operators have also used tools to terminate security and backup-related processes, delete shadow copies, and hinder recovery, indicating a mature double-extortion-style ransomware workflow that combines environment preparation, data theft, and encryption.
The ransomware has been linked to intrusion vectors such as compromised RDP access, SMB-based network scanning, and opportunistic exploitation. Beast has also been observed in campaigns against South Korean organizations. Code overlap and shared operational tooling connect Beast closely to both its predecessor Monster and successor GodDamn, indicating iterative development by the same operator rather than unrelated families using a common brand.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GodDamn ransomware first appeared in May 2026 and analysis of the code revealed that it is the newest iteration of Beast ransomware, itself is a rebrand of Monster ransomware which was first seen in 2022.
The Beast ransomware group is a fairly new one, which sprung from another strain — the so-called Monster ransomware gang. It announced itself in 2024, and began operations as a ransomware-as-a-service (RaaS) scheme in February 2025, launching a data-leak site in July.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
BeastDoor provides process injection capabilities and several builder options, including: Notifications Startup AV-FW Kill Misc Exe Icon
The payload dynamically loads the DLL using LoadLibraryA
The Exe Icon option allows the attacker to change the payload’s icon to improve social engineering effectiveness.
BeastDoor provides process injection capabilities and several builder options, including: Notifications Startup AV-FW Kill Misc Exe Icon
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier ransomware variant associated with Hyadina before the group moved to GodDamn.
Ransomware family described as directly linked to Monster and GodDamn, with GodDamn characterized as a rebrand of Beast.
An earlier ransomware iteration in the same family as GodDamn; the content describes GodDamn as the newest iteration of Beast.
A ransomware family that rebranded from Monster in June 2024 and is described as the predecessor/rebrand lineage for GodDamn.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.