‘GodDamn’ Ransomware Uses BYOVD to Smite US Companies

A Highly Malicious Ransomware Operation Exploits Signed Driver to Wreak Havoc on US Companies

A new wave of ransomware attacks is sweeping across American organizations, courtesy of a group known as Hyadina. This four-year-old ransomware-as-a-service (RaaS) operation has been rebranding itself with new lockers, including the latest iteration, “GodDamn.” What’s particularly concerning about this threat is its use of a malicious kernel driver that was surprisingly signed by Microsoft, allowing it to bypass security software and wreak havoc on infected systems.

Hyadina’s targets have ranged across various sectors, including healthcare, manufacturing, education, and others. Its modus operandi involves deploying a suite of dual-use hacking tools, including legitimate remote monitoring and management (RMM) software, penetration testing programs, and even open-source stealers like Mimikatz. The group’s use of these tools is a stark reminder that even the most seemingly innocuous software can be turned against its users.

The pièce de résistance in Hyadina’s arsenal is PoisonX, a malicious kernel driver that was granted a legitimate Microsoft Hardware Compatibility signature despite being used for nefarious purposes. This signed driver allowed it to kill security-related processes and remove user-mode application programming interface (API) hooks, rendering endpoint security tools ineffective on infected computers. It’s worth noting that the author of PoisonX, “oxfemale,” claimed it as a research tool on GitHub, but its true intentions remain unclear.

The fact that PoisonX was signed by Microsoft raises serious questions about the vetting process for kernel drivers. While Microsoft maintains a Vulnerable Driver Blocklist to prevent such exploits, it’s clear that more needs to be done to protect against these types of attacks. As Symantec’s Brigid O Gorman notes, “Unfortunately, almost every tool is potentially malicious when in the wrong hands.” This highlights the importance of behavioral and adaptive protection measures that can block suspicious behavior on the network, even if it originates from legitimate-seeming tools.

In light of this attack vector, organizations would do well to revisit their security protocols and ensure they’re taking proactive steps to prevent such exploits. This includes implementing robust endpoint detection and response (EDR) solutions that can identify and mitigate malicious activity in real-time. Additionally, ensuring that all software, including kernel drivers, is thoroughly vetted before deployment can go a long way in preventing these types of attacks.


Source: Dark Reading — 2026-07-09