GodDamn Ransomware Cripples Computer Defenses Using PoisonX Weapon

Cybersecurity experts have sounded the alarm over a dangerous new strain of ransomware that is actively blinding antivirus programs before locking up files. Named GodDamn, this aggressive malicious software uses a specific tool known as the PoisonX kernel driver to completely turn off security protections on infected machines. According to a fresh investigation by Symantec’s Threat Hunter Team, the ransomware first popped up on the radar on May 21, 2026. Investigators believe this threat is actually a fresh makeover of an older threat called Beast, which itself grew out of a 2022 malware family known as Monster. The digital masterminds behind this continuous evolution are currently being tracked under the name Hyadina.

How the Intruders Sneak In and Steal Secrets

During a real-world incident investigated in early June 2026, the hackers followed a calculated playbook to infiltrate a target network. While experts still do not know exactly how the hackers first broke into the system, they quickly set up remote access using the popular legitimate tool AnyDesk. Once inside, they unleashed a collection of data-stealing utilities to harvest login information.

This password-grabbing toolkit went to work pulling sensitive credentials out of internet browsers, the built-in Windows Credential Manager, saved network domain data, virtual network sessions, email programs, and wireless network profiles. It even monitored live network data traveling across the system to snatch as much information as possible.

Blinding the Security System from Within

The most terrifying aspect of the attack is how the ransomware disables safety nets using a strategy called “bringing your own vulnerable driver”. In this case, the criminals disguised one of their malicious files as a real security product to throw defenders off the scent. At the same time, they loaded the PoisonX kernel driver onto the computer. What makes PoisonX exceptionally dangerous is that its creators somehow tricked Microsoft into officially signing the file. Because it carries an official digital signature, the Windows operating system trusts it completely and lets it run without raising any red flags.

Once a hacker gains administrative power, dropping a signed but dangerous driver onto a PC is the most reliable way to break in. Security software is completely helpless against this tactic. The rogue driver can immediately terminate the processes running your antivirus or endpoint monitoring programs, stripping the computer naked of any defenses.

In more sneaky scenarios, these drivers do not turn off the antivirus entirely; instead, they strip away its administrative rights so it stays running but cannot block anything. Sometimes, they mess with the core system logs directly, making the security program entirely blind to malicious events happening right under its nose. Notably, PoisonX is also shared among other cybercriminals, including a ransomware group known as The Gentlemen, who pack it into their own defense-breaking toolkits.

Spreading the Infection and Demanding Ransom

To ensure maximum damage, the hackers did not just stop at one computer. They utilized a tool called PsExec to hop from one machine to another across the company’s internal network. As they reached each new machine, they installed AnyDesk and configured it to launch automatically whenever the computer restarted, ensuring they would never lose access.

To speed things up, they automated this entire setup process across multiple computers using a pre-made script. By the second day of June, the attackers had successfully taken over at least ten different systems within the victimized company using this specific sequence.

The actual data encryption phase began the very next day on a separate part of the network. During this particular deployment, the ransomware altered file extensions to match the name of the victimized company rather than utilizing its usual file marker. Once the destruction was complete, the software left behind a ransom note instructing the victims on how to pay up.

According to analysts at CYFIRMA, the note orders the targets to negotiate a payout either through traditional email or by using an encrypted chat application called qTox. Security analysts emphasize that the sudden appearance of the PoisonX driver proves that the Hyadina hacking group is rapidly advancing its techniques, making their digital extortion campaigns harder to stop than ever before.

Privacy Preference Center