Contact us

Threat Intelligence - Cyber Attack News

The latest cyber attack coverage, refreshed daily and archived so you can track how the threat landscape evolves. Stories are aggregated from publicly available security news reporting.

Category — Endpoint Security

← All stories

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

Malware/Endpoint Security

Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It's assessed to be a rebrand of the Beast ransomware, which, in turn, was an enhanced version of Monster , a Delphi-based ransomware that surfaced in March 2022. Broadcom's cybersecurity arm is tracing the developer behind these ransomware families under the moniker Hyadina. In one attack orchestrated by the ransomware operation in early June 2026, the threat actors are said to have leveraged AnyDesk for remote access and used a NirSoft-based credential harvesting toolkit before deploying the ransomware. The exact initial access vector is unknown. The credential harvester is designed to extract sensitive data from common web browsers, W...