New GodDamn Ransomware Family Uses PoisonX Driver to Evade Security Software
Deploy updated anti‑malware signatures and monitor for PoisonX driver activity.
Update endpoint protection to block PoisonX kernel driver, conduct forensic analysis on infected machines, and educate staff on ransomware indicators.
Summary
Cybersecurity researchers have identified a new ransomware family named GodDamn that leverages the PoisonX kernel driver to neutralize security software, enabling rapid defense evasion. The family was first publicly spotted in the wild on May 21 2026 and is believed to be a rebrand of the Beast ransomware, according to a Symantec Threat Hunter Team report. GodDamn’s use of the PoisonX driver allows it to disable antivirus processes and other security controls during execution. The malware also includes a sophisticated dropper that encrypts victim files and demands a ransom payment in cryptocurrency. Analysts warn that the combination of kernel‑level persistence and rapid encryption makes GodDamn a potent threat for enterprises. The report recommends updating endpoint protection signatures and monitoring for kernel‑driver anomalies. Security teams should also review their incident response plans to address the new evasion tactics. The emergence of GodDamn underscores the evolving sophistication of ransomware operators.
Key changes
- GodDamn ransomware identified
- Uses PoisonX kernel driver to neutralize security software
- First spotted May 21 2026
- Rebrand of Beast ransomware
- Includes dropper that encrypts files and demands ransom
- Kernel‑level persistence enables rapid evasion
- Symantec report recommends updating signatures
- Threat highlights need for monitoring driver activity