'GodDamn' Ransomware Uses BYOVD to Smite US Companies

Chronological Source Flow
Back

AI Fusion Summary

The GodDamn ransomware, identified as a rebrand of Beast ransomware, was first spotted on May 21, 2026. This malware employs a BYOVD strategy using the PoisonX kernel driver, which is co-signed by Microsoft. By utilizing this malicious driver, GodDamn effectively neutralizes security software and disables endpoint defenses to evade detection. These attacks specifically target US companies, leveraging the trusted driver to kill security processes and facilitate the ransomware's deployment across infected systems.
Community Comments
Loading updates...
0