SUBJECT PROFILE
Hyadina is a RaaS operation tracked by Symantec since March 2022 through three successive locker rebrands: Monster (2022) → Beast (June 2024) → GodDamn (May 2026). On July 9, 2026, Symantec disclosed the GodDamn variant's use of PoisonX, a custom kernel driver bearing a legitimate Microsoft Hardware Compatibility Publisher signature obtained via GitHub alias 'oxfemale,' enabling a novel BYOVD attack that forcibly blinds endpoint security tools before ransomware deployment. The PoisonX driver was also incorporated into the GentleKiller toolkit distributed to The Gentlemen RaaS affiliates, indicating cross-group tool sharing.
Financial extortion targeting primarily US organizations across opportunistic sectors
OPERATIONAL HISTORY
BYOVD attack using PoisonX Microsoft-signed kernel driver to terminate EDR processes, AnyDesk for remote access and initial persistence, PsExec for lateral movement, Mimikatz for credential dumping, NirSoft credential harvesting toolkit, fake Symantec-branded evasion utility, double extortion with data leak threat, CIS country avoidance, password-protected self-extracting archives for tool delivery
KNOWN INFRASTRUCTURE
GodDamn ransomware locker (significant code overlap with Beast/Monster); PoisonX signed kernel driver (Microsoft WHCP signature — published April 7, 2026 by 'oxfemale' on GitHub); AnyDesk hidden in 'Music' folder; NetScan for network reconnaissance; NirSoft suite; shared PoisonX driver also used in The Gentlemen's GentleKiller affiliate toolkit