news.mlab.sh
Back to the feed
threat-intel

'GodDamn' Ransomware Uses BYOVD to Smite US Companies

High
Image: Dark Reading
Summary

The ransomware group Hyadina, operating under the name "GodDamn," is leveraging a Microsoft-approved, malicious kernel driver – dubbed "PoisonX" – to infiltrate US organizations and deploy its ransomware. They utilize a combination of legitimate tools, including RMM software and open-source credential stealers, alongside a Bring Your Own Vulnerable Driver (BYOVD) attack to bypass security measures. The group’s tactics highlight the ongoing challenge of defending against ransomware by relying solely on driver blocklists due to the time lag between identification and deployment.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.