A new breed of ransomware, dubbed “GodDamn,” has emerged in the US, utilizing a malicious yet Microsoft-approved driver to evade security software and wreak havoc on unsuspecting organizations. This sophisticated attack vector, known as BYOVD (Bring Your Own Vulnerable Driver), exploits a loophole in Windows kernel security, allowing attackers to kill security-related processes and disable endpoint protection tools.
The threat group behind GodDamn, Hyadina, has been active for four years and has a reputation for targeting American organizations across various sectors, including healthcare, manufacturing, and education. What’s more alarming is that their modus operandi involves using legitimate software and penetration testing tools to gain access to their targets’ systems. In one recent case, they employed a combination of dual-use hacking tools, including remote monitoring and management (RMM) software and 14 open-source programs used for credential theft.
The attack unfolds with the loading of AnyDesk, a legitimate RMM platform, into an infected computer’s Music folder. This is followed by the deployment of a binary named symantec.exe, which drops PoisonX, a malicious kernel driver that was inexplicably granted a Microsoft Hardware Compatibility signature. PoisonX then proceeds to kill security-related processes and remove user-mode API hooks, crippling endpoint security tools running on host computers.
What’s striking about this attack is the use of PoisonX, a signed driver that has been published on GitHub as a “research tool.” While its author claims to be a Russian security researcher specializing in reverse engineering and penetration testing, Symantec has labeled it malware due to its lack of legitimate usage. The fact that Microsoft inadvertently granted PoisonX a signature raises questions about the vetting process for kernel drivers.
The implications of this attack are far-reaching, highlighting the need for robust endpoint protection measures and advanced threat detection capabilities. As Symantec’s Brigid O Gorman notes, “Unfortunately, almost every tool is potentially malicious when in the wrong hands.” Behavioral and adaptive protection mechanisms can help block suspicious behavior on the network, even if it originates from legitimate-seeming tools.
To mitigate this risk, organizations should prioritize implementing robust security controls, including behavioral monitoring and advanced threat detection. Additionally, Microsoft’s Vulnerable Driver Blocklist can serve as a valuable resource for identifying potential threats. As the cybersecurity landscape continues to evolve, it’s essential for organizations to stay vigilant and proactive in defending against emerging threats like GodDamn ransomware.
Source: Dark Reading — 2026-07-09