New 'GodDamn' Ransomware Uses a Rogue Driver to Kill Antivirus Software
Symantec links the May 2026 strain to the older Beast ransomware family, with medium confidence it's a rebrand.

Key points
- Symantec's Threat Hunter Team first observed GodDamn ransomware in the wild on May 21, 2026.
- The malware ships with a Windows kernel driver called PoisonX that shuts down antivirus and endpoint security tools before files get locked.
- Symantec assesses GodDamn to be a rebrand of the earlier Beast ransomware family.
- The attack pattern fits a wider trend of criminal groups abusing signed or vulnerable drivers to blind defenders.
Security researchers have flagged a new ransomware strain, malicious software that locks a company's files and demands payment for their release, going by the name GodDamn.
The malware carries a tool called PoisonX: a kernel driver, meaning software that runs at the deepest, most trusted level of Windows, from where it can reach up and switch off the very security products meant to catch it.
Symantec's Threat Hunter Team says it first saw GodDamn in the wild on May 21, 2026. Symantec assesses with medium confidence that GodDamn is a rebrand of Beast, an older criminal ransomware family. The original reporting was published by The Hacker News.
Our earlier story on 9 July 2026 found that a rebranded gang called Hyadina is using a legitimately Microsoft-stamped driver to kill antivirus before locking victims' files, a detail that sharpens the picture Symantec is drawing here.
What does this actually mean for a normal business?
If GodDamn reaches a company's network, the antivirus on those machines may go quiet right before files are scrambled. Staff and IT teams often notice only when computers start showing ransom notes.
Criminal crews have spent recent years buying or crafting kernel drivers to disable endpoint detection and response tools (EDR), the modern replacements for traditional antivirus. Analysts call this class of tool an "EDR killer". What's notable about GodDamn is the pairing: the file-locking payload and PoisonX appear bundled together as a ready-made kit, which lowers the skill bar for an attacker considerably.
Who is behind it?
Attribution is thin, and worth flagging honestly.
Symantec's link to Beast rests on code and behaviour overlaps, not on a named group or country. No public indication places this with a nation-state crew or a known ransomware-as-a-service brand. Treat confident naming you see elsewhere with caution until a second vendor corroborates it.
Beast was a financially motivated criminal operation, so a rebrand fits that same profile. Capability, a working driver-based defence killer, is not the same thing as intent.
How does the driver trick work?
Windows will only load kernel drivers that are digitally signed, stamped as trustworthy by a recognised publisher. Criminals get around this in two ways.
Some steal or buy legitimate signing certificates. Others use a technique called "bring your own vulnerable driver": load a real, signed driver with a known flaw, then abuse that flaw to run their own code with kernel-level privileges.
Symantec has not yet published the full technical breakdown of which route PoisonX takes. That detail matters, because it changes what defenders should prioritise blocking.
Should you worry if you're not in IT?
If a company you deal with gets hit, you may see service outages, record delays, or a breach notification letter weeks later. Follow any official letter's instructions carefully and be wary of emails or calls claiming to be from the affected company. Criminals routinely use the confusion around a public incident to run follow-on scams.
For businesses, the practical steps right now are straightforward: confirm your security software alerts on new kernel drivers being loaded, and keep backups offline where ransomware can't reach them.



