'GodDamn' Ransomware Uses BYOVD to Smite US Companies
The ransomware group Hyadina, operating under the name "GodDamn," is leveraging a Microsoft-approved, malicious kernel driver – dubbed "PoisonX" – to infiltrate US organizations and deploy its ransomware. They utilize a combination of legitimate tools, including RMM software and open-source credential stealers, alongside a Bring Your Own Vulnerable Driver (BYOVD) attack to bypass security measures. The group’s tactics highlight the ongoing challenge of defending against ransomware by relying solely on driver blocklists due to the time lag between identification and deployment.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
