Briefing

New GodDamn Ransomware Family Uses PoisonX Driver to Evade Security Software

security
by [email protected] (The Hacker News) ·

Deploy updated anti‑malware signatures and monitor for PoisonX driver activity.

What to do now

Update endpoint protection to block PoisonX kernel driver, conduct forensic analysis on infected machines, and educate staff on ransomware indicators.

Summary

Cybersecurity researchers have identified a new ransomware family named GodDamn that leverages the PoisonX kernel driver to neutralize security software, enabling rapid defense evasion. The family was first publicly spotted in the wild on May 21 2026 and is believed to be a rebrand of the Beast ransomware, according to a Symantec Threat Hunter Team report. GodDamn’s use of the PoisonX driver allows it to disable antivirus processes and other security controls during execution. The malware also includes a sophisticated dropper that encrypts victim files and demands a ransom payment in cryptocurrency. Analysts warn that the combination of kernel‑level persistence and rapid encryption makes GodDamn a potent threat for enterprises. The report recommends updating endpoint protection signatures and monitoring for kernel‑driver anomalies. Security teams should also review their incident response plans to address the new evasion tactics. The emergence of GodDamn underscores the evolving sophistication of ransomware operators.

Key changes

  • GodDamn ransomware identified
  • Uses PoisonX kernel driver to neutralize security software
  • First spotted May 21 2026
  • Rebrand of Beast ransomware
  • Includes dropper that encrypts files and demands ransom
  • Kernel‑level persistence enables rapid evasion
  • Symantec report recommends updating signatures
  • Threat highlights need for monitoring driver activity

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting