A Microsoft-Approved Driver Is Helping 'GodDamn' Ransomware Gut US Security Tools
A rebranded criminal gang called Hyadina is using a signed Windows driver to kill antivirus software before locking victims' files. The driver carries a legitimate Microsoft stamp, and nobody knows quite how that happened.

Key points
- Hyadina, a ransomware-as-a-service group that's been running for roughly four years, rebranded in 2025 and is now deploying a file-locking program called GodDamn against US organisations.
- A malicious driver called PoisonX, published to GitHub on 7 April 2025, carries an authentic Microsoft signature that lets it run at the deepest level of Windows and disable security software.
- Symantec researchers observed a live attack beginning 29 May 2026, in which the gang used 14 separate hacking tools before dropping ransomware.
- Microsoft maintains a blocklist to stop dangerous drivers, but updates can lag weeks behind newly discovered threats.
- PoisonX's author describes herself on LinkedIn as a Russian security researcher; Dark Reading attempted contact but received no response before publication.
A criminal gang that locks companies' files and demands payment recently used a piece of software Microsoft itself had certified as safe, Symantec reported this week. The group is Hyadina. Its new ransomware, the software it uses to encrypt and hold victims' data hostage, goes by GodDamn.
How did the attackers get past the security software?
They brought a weapon Microsoft had already approved. At the heart of this attack is a kernel driver, a low-level program that Windows grants near-total control over a computer, sitting beneath antivirus tools and almost everything else. Hyadina's driver, PoisonX, carries a genuine Microsoft Hardware Compatibility signature, meaning Windows treats it as trusted software.
Once loaded, PoisonX killed every security process on the machine. It also stripped out API hooks, the monitoring points security tools use to watch for suspicious behaviour, leaving defences effectively blind.
Nobody knows how the group obtained a valid signature. Symantec researcher Brigid O Gorman said that in hindsight Microsoft shouldn't have signed PoisonX, but acknowledged the team doesn't know how the attackers may have tricked Microsoft into doing so.
Microsoft keeps a Vulnerable Driver Blocklist, a running catalogue of dangerous drivers Windows will refuse to load even if they carry a legitimate signature. The problem, O Gorman notes, is that the gap between a bad driver being spotted and the blocklist update reaching company computers is "often weeks, not hours." Attackers move faster. Our earlier story on SprySOCKS Windows variants using driver-level hiding showed the same structural weakness: signing and blocklist latency combine to hand attackers a window that defenders can't reliably close.
The attack started simply. On 29 May, an unexpected copy of AnyDesk, a legitimate remote-desktop program, turned up in a victim's Music folder. Not where it belongs, and not authorised. A day later, PoisonX arrived on a second machine, dropped by a file named symantec.exe.
After that, Hyadina deployed 14 tools for stealing passwords, reading saved browser credentials and moving between computers on the same network. Thirteen came from NirSoft, a free Windows utilities site. One was Mimikatz. Legitimate tools leave far fewer obvious traces than purpose-built malware, and that's precisely the point.
Should you worry?
Yes, if your organisation runs Windows and hasn't verified its driver blocklist update cadence. The first warning sign in this case was AnyDesk appearing in the wrong folder on the wrong date. Behavioural monitoring that flags unusual software in unusual locations would've caught it before PoisonX ever ran.
Confirm that Microsoft's Vulnerable Driver Blocklist updates are applied automatically. Don't wait for the quarterly patch window. The blocklist only helps if it's current.



