news.mlab.sh
Back to the feed
ransomware

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

High
Image: The Hacker News
Summary

The GodDamn ransomware family, a rebrand of Beast ransomware (originally based on Monster), is utilizing a newly discovered malicious driver called PoisonX to disable endpoint defenses and gain access to systems. Threat actors are leveraging AnyDesk for remote access and a custom credential harvesting toolkit to compromise targets, with the goal of deploying the ransomware. The attack is characterized by lateral movement using PsExec and AnyDesk, and a reusable installer to streamline the deployment process.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.