DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // HYADINA-GODDAMNFIRST SEEN: MAR 2022

Hyadina

ALSO KNOWN AS: GodDamn (current locker), Beast (prior locker), Monster (original locker 2022)
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (avoids CIS countries — consistent with Russian-speaking criminal norms)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:MAR 2022
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL65/100
RESOURCES65/100
PERSISTENCE68/100
STEALTH60/100
IMPACT74/100

Hyadina is a RaaS operation tracked by Symantec since March 2022 through three successive locker rebrands: Monster (2022) → Beast (June 2024) → GodDamn (May 2026). On July 9, 2026, Symantec disclosed the GodDamn variant's use of PoisonX, a custom kernel driver bearing a legitimate Microsoft Hardware Compatibility Publisher signature obtained via GitHub alias 'oxfemale,' enabling a novel BYOVD attack that forcibly blinds endpoint security tools before ransomware deployment. The PoisonX driver was also incorporated into the GentleKiller toolkit distributed to The Gentlemen RaaS affiliates, indicating cross-group tool sharing.

Financial extortion targeting primarily US organizations across opportunistic sectors

BYOVD attack using PoisonX Microsoft-signed kernel driver to terminate EDR processes, AnyDesk for remote access and initial persistence, PsExec for lateral movement, Mimikatz for credential dumping, NirSoft credential harvesting toolkit, fake Symantec-branded evasion utility, double extortion with data leak threat, CIS country avoidance, password-protected self-extracting archives for tool delivery

HEALTHCARE
MANUFACTURING
EDUCATION
US ENTERPRISE

GodDamn ransomware locker (significant code overlap with Beast/Monster); PoisonX signed kernel driver (Microsoft WHCP signature — published April 7, 2026 by 'oxfemale' on GitHub); AnyDesk hidden in 'Music' folder; NetScan for network reconnaissance; NirSoft suite; shared PoisonX driver also used in The Gentlemen's GentleKiller affiliate toolkit

FILE DATE: MAR 2022
Monster RaaS Launch
Hyadina launched Monster ransomware as a Delphi-based locker targeting 32-bit Windows systems via a traditional RaaS affiliate model, with consistent CIS avoidance.
FILE DATE: JUN 2024
Beast Rebrand
Hyadina rebranded Monster to Beast, maintaining the same operational toolkit and █████████████████████ upgrading the locker codebase.
FILE DATE: JUN 2026
GodDamn BYOVD Attack (Disclosed July 9, 2026)
Hyadina deployed the GodDamn locker against an unidentified US organization using the PoisonX Microsoft-signed kernel driver to blind EDR tools on 10 hosts before encrypting the environment, marking a significant escalation in defensive evasion capability.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn