PoisonX is a malicious Windows kernel driver used to disable or weaken endpoint security controls from kernel mode. It has been observed carrying a valid Microsoft Hardware Compatibility signature, allowing it to load as a trusted driver on Windows systems despite being purpose-built for malicious use. Its core role is defense evasion: it terminates security-product processes, can remove or bypass user-mode API hooks used by EDR products, and has been reported in some campaigns to expose kernel interfaces that let user-mode components kill arbitrary processes and interfere with security telemetry.
PoisonX has been used in multiple intrusion contexts during 2026. In financially motivated ransomware activity attributed to the Hyadina ecosystem, operators deployed PoisonX before launching the GodDamn ransomware, using it alongside AnyDesk, credential-harvesting utilities, Mimikatz, and PsExec to reduce endpoint visibility, steal credentials, expand access, and then encrypt systems. Hyadina-linked activity has primarily targeted enterprise Windows environments, including organizations in healthcare, manufacturing, and education, with reporting indicating a concentration on U.S. victims. PoisonX has also been documented in spearphishing campaigns targeting organizations in Japan and China, where it was delivered with PXDropper and the 10FXRAT remote access trojan. In those campaigns, phishing lures led to downloader and DLL-sideloading chains that installed the driver, established persistence, and enabled follow-on remote access and credential theft.
Operationally, PoisonX is associated with BYOVD-style defense evasion, although some reporting distinguishes it from classic abuse of preexisting vulnerable drivers because PoisonX itself appears to be a malicious driver that was successfully signed. Later related campaigns rotated to other signed drivers, underscoring the same tradecraft objective of kernel-level impairment of defenses. PoisonX represents a notable escalation in attacker capability because it gives intruders a reliable way to blind or degrade endpoint protections before post-exploitation or ransomware deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
PoisonX is a signed Windows kernel driver observed in an April 2026 spear-phishing campaign against organizations in Japan and China.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
From here, the attackers used an executable file disguised as a Symantec product to drop PoisonX, a malicious kernel driver which carries a legitimate Microsoft Windows Hardware Compatibility Publisher signature into the system driver store and is used to terminate security product processes, further lowering the defenses of the system.
この攻撃では、「PoisonX」と呼ばれるカーネルドライバと遠隔操作機能を持つ「10FXRAT(別名:PoisonX RAT)」が悪用されていることを確認しています。
22 distinct techniques documented for this family, organized by ATT&CK tactic.
...the Microsoft-signed PoisonX kernel driver to disable endpoint security through a BYOVD-style defense evasion technique before deploying the ransomware.
その後、ファイル名と同じ名称でWindowsサービスとして登録し、このサービスを起動します。... 「DevCfgCC.sys」というファイル名で永続化ディレクトリへ書き出し、OSの起動時に自動的に読み込まれるよう、システムにサービスとして登録します。
drop PoisonX, a malicious kernel driver which carries a legitimate Microsoft Windows Hardware Compatibility Publisher signature into the system driver store and is used to terminate security product processes
マルウェア内部にハードコードされている暗号化された10FXRAT関連ファイル...を、Incremental XORを用いて復号します。
the attackers used an executable file disguised as a Symantec product to drop PoisonX
これを受け取ったドライバは、WindowsのカーネルAPIや、正規のネットワーク監視ドライバ(¥Driver¥nsiproxy、¥Device¥Tcpなど)をフックし、指定されたPIDのプロセス情報と通信記録をシステムから除外します。これにより、OSのプロセス一覧から自身の存在を消し去り、タスクマネージャーやEDR等の各種システム監視ツールから、プロセスおよびC2サーバとの不正な通信活動を隠蔽することが可能となります。
the signed host side-loads the attacker DLL, which decrypts the bundled cache to stage the driver and RAT.
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Microsoft-signed Windows kernel driver used to terminate security-related processes and remove user-mode API hooks used by EDR products, thereby disabling endpoint protections prior to ransomware deployment.
A malicious kernel driver used by the GodDamn ransomware strain to terminate or disable endpoint security defenses before encryption.
A malicious Microsoft-signed kernel driver used to kill antivirus/EDR processes, strip security agents of required rights, or tamper with kernel notification records so defenses stop receiving events and go blind.
A malicious Microsoft-signed kernel driver used to disable endpoint defenses by killing security processes and removing user-mode API hooks before ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.