Beast is a ransomware-as-a-service family in the Hyadina lineage, developed as a rebrand of Monster ransomware and subsequently rebranded as GodDamn. The family has operated since 2022 under its Monster identity; Beast emerged in 2024 and expanded the lineage from Windows to Linux and VMware ESXi environments. Beast and its successors have targeted organizations including healthcare, manufacturing, pharmaceutical, and other enterprise sectors, while exhibiting avoidance of systems associated with Commonwealth of Independent States locales.
Beast encrypts files and supports extortion operations, including data-theft-associated pressure. Its ransomware functionality includes terminating security, database, office, and backup-related processes and services; deleting volume shadow copies and backups; enumerating volumes, network hosts, and network shares; and encrypting accessible network locations. Samples associated with the Beast/GodDamn lineage can establish Windows persistence through self-copying and autorun registration, and use locale checks to avoid execution in selected regional and language environments. Operators have used remote-access software, credential-harvesting tools, network-scanning utilities, and remote execution tooling to expand access before ransomware deployment. Later Hyadina activity added kernel-level security-product impairment through the malicious signed PoisonX driver.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GodDamn ransomware first appeared in May 2026 and analysis of the code revealed that it is the newest iteration of Beast ransomware, itself is a rebrand of Monster ransomware which was first seen in 2022.
The Beast ransomware group is a fairly new one, which sprung from another strain — the so-called Monster ransomware gang. It announced itself in 2024, and began operations as a ransomware-as-a-service (RaaS) scheme in February 2025, launching a data-leak site in July.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
BeastDoor provides process injection capabilities and several builder options, including: Notifications Startup AV-FW Kill Misc Exe Icon
The payload dynamically loads the DLL using LoadLibraryA
The Exe Icon option allows the attacker to change the payload’s icon to improve social engineering effectiveness.
BeastDoor provides process injection capabilities and several builder options, including: Notifications Startup AV-FW Kill Misc Exe Icon
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Beast (GodDamn) is configurable ransomware that avoids encrypting systems in CIS-related locales and UI languages. It copies itself to %LOCALAPPDATA% under a MachineGuid-named directory, establishes HKCU Run-key persistence, clears the Recycle Bin, deletes WMI Shadow Copy instances, terminates processes and services associated with databases, office applications, backups, and security products, enumerates network shares and hosts, and encrypts files. Encrypted files receive a .[8-character ID-8-character ID].goddamn extension. It can generate ransom notes threatening data leakage after 12 hours and includes optional C2 reporting before and after encryption; C2 was disabled in the analyzed sample.
An earlier ransomware variant associated with Hyadina before the group moved to GodDamn.
Ransomware family described as directly linked to Monster and GodDamn, with GodDamn characterized as a rebrand of Beast.
An earlier ransomware iteration in the same family as GodDamn; the content describes GodDamn as the newest iteration of Beast.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.