Monster is a ransomware family that emerged in 2022 and was operated as a ransomware-as-a-service offering by the developer tracked as Hyadina. Primarily written in Delphi, it targeted 32-bit Windows systems and avoided machines that appeared to be located in Commonwealth of Independent States countries. Its principal function is file encryption for ransom-based extortion.
Monster-associated attacks used legitimate remote-access software and credential-recovery utilities during the stages preceding ransomware deployment. AnyDesk was observed in pre-ransomware activity leading to Monster infections, while affiliates used Mimikatz and NirSoft password-recovery tools to harvest credentials. These utilities formed part of the operators’ intrusion toolset rather than demonstrating native credential-stealing functionality in the ransomware itself.
Hyadina rebranded Monster as Beast in June 2024, subsequently extending the ransomware lineage to Linux and VMware ESXi. GodDamn, first observed in May 2026, is a later rebrand of Beast. Code analysis links the three families to a continuing development lineage; the expanded platform support and newer defense-impairment tooling belong to successor operations and should not be assumed to be capabilities of the original Monster payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GodDamn ransomware first appeared in May 2026 and analysis of the code revealed that it is the newest iteration of Beast ransomware, itself is a rebrand of Monster ransomware which was first seen in 2022.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier ransomware variant associated with Hyadina before the group moved to GodDamn.
Earlier ransomware family from 2022 that the article links by lineage and code overlap to Beast and GodDamn.
An earlier ransomware form first seen in 2022 and described as the predecessor to Beast within the same family later dubbed Hyadina.
An earlier ransomware family in the same lineage that emerged in November 2022 and later rebranded to Beast.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.