GodDamn Ransomware (Hyadina) Deploys Microsoft-Signed Malicious Kernel Driver PoisonX to Blind EDR Before Encryption
Symantec's Threat Hunter Team disclosed on July 9 that the Hyadina RaaS group's newest locker, GodDamn — the third iteration after Monster (2022) and Beast (2024) — weaponizes PoisonX (g11.sys), a malicious kernel driver that obtained a legitimate Microsoft Windows Hardware Compatibility Publisher signature and is now capable of terminating EDR processes, stripping API hooks, and killing CrowdStrike Falcon via crafted IOCTL before encryption begins. Unlike standard BYOVD attacks that exploit flaws in legitimate drivers, PoisonX was purpose-built for offense and has no patch surface — Microsoft's Vulnerable Driver Blocklist is the only systemic control, but updates lag days to weeks behind discovery. The driver has also been incorporated into the GentleKiller toolkit distributed to affiliates of The Gentlemen RaaS, with PoisonX now implicated across 478+ victims in 70+ countries.
The driver has also been incorporated into the GentleKiller toolkit distributed to affiliates of The Gentlemen RaaS, with PoisonX now implicated across 478+ victims in 70+ countries.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.