Analysis financehealthcare
GodDamn / Hyadina -- The Beast Rebrand That Ships With a Microsoft-Signed EDR Killer
The threat actor Symantec tracks as Hyadina has run three successive ransomware families since 2022. The latest, GodDamn, arrives paired with PoisonX -- a kernel driver that carries a valid Microsoft signature and kills endpoint defences before encryption starts. This is not a BYOVD attack. The driver was built for this purpose, and then it got a legitimate certificate.