ransomware
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
High
Summary
The GodDamn ransomware family, a rebrand of Beast ransomware (originally based on Monster), is utilizing a newly discovered malicious driver called PoisonX to disable endpoint defenses and gain access to systems. Threat actors are leveraging AnyDesk for remote access and a custom credential harvesting toolkit to compromise targets, with the goal of deploying the ransomware. The attack is characterized by lateral movement using PsExec and AnyDesk, and a reusable installer to streamline the deployment process.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
