Article may be outdated

This article is 89 days old. Some details may have changed since publication.

Infosecurity Magazine·3 min read·medium

New Ransomware Exploits Malicious Driver to Remove Security Protection

D
Danny Palmer
New Ransomware Exploits Malicious Driver to Remove Security Protection
✦AI Summary

A ransomware family known as Hyadina is using malicious, Microsoft-signed drivers to disable security software on infected endpoints. The attackers gain initial access through compromised accounts before deploying tools to steal credentials and encrypt data.

Why it matters

The use of legitimate digital signatures on malicious drivers represents a significant escalation in malware sophistication, making it harder for standard security tools to detect threats.

✦Dive DeeperCreate a free account to unlock

The latest incarnation of a family of ransomware which has been hitting organizations since 2022 has evolved to exploit Microsoft-signed malicious drivers to prevent endpoint defenses from detecting and disrupting its attacks.

Detailed by cybersecurity researchers at Symantec, GodDamn ransomware first appeared in May 2026 and analysis of the code revealed that it is the newest iteration of Beast ransomware, itself is a rebrand of Monster ransomware which was first seen in 2022. All three forms of ransomware are part of a family which has been dubbed Hyadina.

In a blog post published on July 9 , Symantec researchers said the attackers were spotted leveraging AnyDesk, a remote desktop application, which was hidden on the affected endpoint in a folder named 'Music' and made outbound connections to unknown IP addresses.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in