GodDamn is a Windows ransomware family first publicly observed in 2026 and assessed to be the latest rebrand in the Monster → Beast → GodDamn lineage associated with the Hyadina ransomware-as-a-service operation. Code overlap and recurring tradecraft link it to earlier Hyadina lockers dating back to 2022. The group has been reported to primarily target organizations in the United States while avoiding victims in former Soviet countries, with prior victimology including healthcare, manufacturing, and education.
GodDamn is notable for pairing conventional ransomware deployment with stronger pre-encryption intrusion activity and kernel-level defense evasion. In observed intrusions, operators used remote access software to maintain hands-on access, deployed a fake security-branded executable, and installed the PoisonX kernel driver before encryption. PoisonX is a malicious Microsoft-signed driver used to terminate security processes, remove user-mode API hooks, and otherwise impair endpoint protection visibility and response. Researchers assessed this use of PoisonX as a significant escalation in Hyadina’s defensive evasion capability.
Post-compromise activity associated with GodDamn has included extensive credential theft and reconnaissance using NirSoft utilities and Mimikatz, including recovery of credentials from browsers, email clients, messaging applications, Wi-Fi profiles, and Windows credential stores, as well as capture of live network traffic. Operators then used the stolen access to expand control, seek elevated privileges, and move laterally across enterprise networks with PsExec. AnyDesk was also installed on additional hosts and configured for persistence through Windows services, indicating deliberate staging before ransomware execution.
Once sufficient access is established, GodDamn encrypts files and drops a ransom note. Observed campaigns have used either the .God8Damn extension or a victim-specific extension derived from the targeted organization’s name. The family’s operational pattern reflects a financially motivated enterprise ransomware workflow centered on stealthy remote access, credential theft, lateral movement, and pre-encryption disabling of defenses rather than immediate smash-and-grab encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GodDamn ransomware first appeared in May 2026 and analysis of the code revealed that it is the newest iteration of Beast ransomware, itself is a rebrand of Monster ransomware which was first seen in 2022.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Perspective The observed behavior aligns with several MITRE ATT&CK techniques, including: ... Windows Management Instrumentation
MITRE ATT&CK Perspective The observed behavior aligns with several MITRE ATT&CK techniques, including: ... Registry Modification
The initial infection vector could not be determined, with the attacker installing AnyDesk on the first victim machine in the Music folder, suggesting a manual action by an attacker with prior access.
MITRE ATT&CK Perspective The observed behavior aligns with several MITRE ATT&CK techniques, including: ... Process Injection
This binary dropped PoisonX, a malicious kernel driver signed by “Microsoft Windows Hardware Compatibility Publisher.” The PoisonX driver works similarly to a signed vulnerable driver in bring-your-own-vulnerable-driver (BYOVD) attacks
AnyDesk is registered as an auto-start Windows service to survive reboots.
After deploying PoisonX for detection evasion, the GodDamn ransomware attacker deployed a comprehensive suite of 14 credentials-harvesting tools comprising Mimikatz and 13 NirSoft tools
The attacker also deployed NetScan, which could be used to map the victim’s network.
Defense Evasion GodDamn employs multiple techniques to avoid detection. These include: Kernel driver abuse Security process termination
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware payload used by the Hyadina group to encrypt victim systems after the attackers disable endpoint protections, steal credentials, and move laterally.
A ransomware strain that uses the PoisonX kernel driver to disable endpoint defenses prior to encrypting victim systems.
Ransomware assessed as a rebrand in the Monster -> Beast -> GodDamn lineage. It disables or blinds endpoint defenses before encryption, using the Microsoft-signed PoisonX kernel driver in a BYOVD-style attack, a fake Symantec user-mode killer, credential theft via NirSoft tools, and lateral movement with PsExec and AnyDesk.
Ransomware deployed in a June 2026 attack; the article describes it as a rebranding of Beast with significant code overlap and as the final payload used after credential collection and defense evasion activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.