DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
CRITICAL#ransomware

GodDamn Ransomware (Hyadina) Deploys Microsoft-Signed Malicious Kernel Driver PoisonX to Blind EDR Before Encryption

Symantec's Threat Hunter Team disclosed on July 9 that the Hyadina RaaS group's newest locker, GodDamn — the third iteration after Monster (2022) and Beast (2024) — weaponizes PoisonX (g11.sys), a malicious kernel driver that obtained a legitimate Microsoft Windows Hardware Compatibility Publisher signature and is now capable of terminating EDR processes, stripping API hooks, and killing CrowdStrike Falcon via crafted IOCTL before encryption begins. Unlike standard BYOVD attacks that exploit flaws in legitimate drivers, PoisonX was purpose-built for offense and has no patch surface — Microsoft's Vulnerable Driver Blocklist is the only systemic control, but updates lag days to weeks behind discovery. The driver has also been incorporated into the GentleKiller toolkit distributed to affiliates of The Gentlemen RaaS, with PoisonX now implicated across 478+ victims in 70+ countries.

The driver has also been incorporated into the GentleKiller toolkit distributed to affiliates of The Gentlemen RaaS, with PoisonX now implicated across 478+ victims in 70+ countries.

This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.

For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.

STAY AHEAD OF THREATS
Daily intel briefs and IOC packages — delivered to your inbox the moment a new advisory drops.
SUBSCRIBE — $29/MO →
SHARE BRIEF:✕ Post on Xin Share on LinkedIn