CyberWire Daily - A beast by any other name. [Research Saturday]

Episode Date: September 12, 2026

Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disabl...e Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques to evade defenses. In a recent attack, the threat actors used AnyDesk for remote access, a broad credential-harvesting toolkit, and the PoisonX malicious kernel driver to disable endpoint security before deploying the ransomware. The activity highlights Hyadina’s continued development of its ransomware operations and an escalation in its defense-evasion capabilities. The research and executive brief can be found here: ⁠⁠⁠⁠GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Yes, you can have an enterprise network that's secure and reliable and high performance. And no, you don't need to choose the best two out of three. With meter, you can get the end-to-end network built from the ground up, fast to deploy, and easy to manage. That's because meter is software-led for easy installation, maintenance, and control for everything running on your enterprise network. Hardware, firmware, and software all working together from the start seamlessly on a unified platform that's secure by design. You can't protect what you don't know exists, which is why meter gives you comprehensive visibility into wired and wireless routing, switching, firewalls, DNS security, and VPNs. You'll really know what's running on your network down to the most granular client level.
Starting point is 00:01:03 Step off the hardware box upgrade treadmill and switch to the hardware. to meter for a predictable fee and free up your team to spend time on all the other things that keep your business running. Try it out for yourself and book a demo online at meter.com slash cyberwire. That's M-E-T-E-R dot com slash cyberwire. Hello everyone and welcome to the Cyberwires Research Saturday. I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting ourselves in a rapidly evolving cyberspace. Thanks for joining us. This is like a rather third rebrand that we're aware of.
Starting point is 00:02:05 So they had the monster ransomware that they started out with back in 2022. Then they rebranded to Beast. And now they have Goddam. And also we've seen in some of their code as well, 666. So they seem to have this kind of a beast, beastly, I suppose. running through their ransomware names. That's Bridget O'Gorman, senior intelligence analyst on the Semantec Threathunter team. The research we're discussing today is titled GD Ransomware. Latest Beast rebrand uses malicious driver to disable defenses. I mean, I suppose, ransomware, well, threat actors in general have a bit of a history of, you know,
Starting point is 00:02:52 trying to be a little bit controversial sometimes with their names or with the kind of messes of even code and things like that. So I guess they're carrying out a tradition in a way in that sense. Do you suppose there's anything to be read into when a ransomware group continues to rebrand itself like this? I mean, it's definitely not unusual for ransomware groups to rebrand. I think generally it's in a way I suppose to take, sometimes it's trying to take the heat off of themselves, you know. I mean, beast, monster, they would be sort of well-known enough. names, but they wouldn't be hugely, I suppose, controversial ransomware brands. But in the past, I think, we have seen, you know, other, other ransomware families rebrand in a situation where
Starting point is 00:03:41 maybe there's a lot of kind of pressure coming under them, maybe from law enforcement, maybe they've, you know, done a particularly, a particularly controversial attack that maybe has put a lot of heat on them. And so that can, you know, I suppose inspire them to rebrand. I mean, we've seen a few examples of that in the past. We saw the, you know, dark side ransomware, which was using the colonial pipeline attack in the US, which disrupted fuel supply on the East Coast back in 2020, 2020, 2021, back in COVID times.
Starting point is 00:04:16 And I know that was hugely, you know, met a lot of headlines, very controversial. And then that led to the group behind us who we trackers Corrieed. they then rebranded to black matter after that. And then they subsequently rebranded again to the noborous Black Cat Ransomber family, which appears to be shut down at the moment. But, you know, it's very possible they will come around again. So I think rebranding is generally a way to try and maybe take a bit of the heat off of these ransomware families. And sometimes I think maybe it can be driven as well if there's kind of fallouts,
Starting point is 00:04:45 perhaps between ransomware actors as well, and that maybe there can be kind of a, you know, group that splits off and perhaps rebrands to a different identity. as well. Well, let's walk through this attack from the beginning here. What are the first signs that something is wrong? So the first sign we saw in this instance was there was suspicious anodesk activity on the victim network, I suppose. We didn't see what the vector exactly used was, so we don't know if they got in with phishing emails or if they got in by exploiting vulnerabilities. The first kind of suspicious activity we saw was an antiske being installed. on a computer in an unusual location
Starting point is 00:05:26 it was installed under the music folder so that was kind of the first thing that I suppose sparked a bit of suspicion I guess in this attack because it kind of indication you know someone had because it was in such an unusual location that someone had gone in there
Starting point is 00:05:40 and kind of manually installed it as well you know it wasn't even just kind of automated installation when it did something like that and then we saw various connections we made to AdiDesk infrastructure And then we saw the attackers starting to deploy their kind of defense evasion portion of their attack,
Starting point is 00:05:59 which was one of the interesting parts of this attack as well. So part of that was that they downloaded onto the computer a defense evasion tool, which they were masquerading as a semantic executable. So they named this tool semantic.exe. And that was also installed in the music folder and trying to impersonate semantic product. though it didn't have any, you know, there was no legitimacy to that at all. And then that was used to launch a kernel driver called Poison X. So this was one of the interesting parts of this attack.
Starting point is 00:06:30 So I suppose BYOVD, as we call it, the bring your own vulnerable driver tactic. It's something we're seeing so much now in ransomware attacks, like really increasingly seeing, and we're seeing attackers use this BIOVD technique to disable security software most of the time. that is what it is being used for. And the Poison X driver that was used in this particular attack is relatively kind of new on the scene. I think it was first seen earlier on this year where it was used in about April it was documented first.
Starting point is 00:07:04 And in that case it was used to disable crowd strike in an attack. But this is, I believe, is the first time we've seen it used alongside a ransomware family as well. Now, one of the things that caught my eye was that driver was signed by Microsoft. What's the significance of that? I mean, it's significance, I suppose, in a few different ways. You know, generally, most modern versions of Windows now, drivers have to be signed or they won't be loaded.
Starting point is 00:07:35 So attackers always want, I suppose, to gain access to these signed drivers. Now, generally what we see when attackers are using this B-Y-O-V-D technique is they are basically exploiting of vulnerability. in what is otherwise a legitimate driver and using that then to basically kind of side load or install their malware and their malicious activity onto the victim network. So, you know, we'd see things like that with ghost driver.
Starting point is 00:08:07 Like I'd say, that's kind of a publicly available tool but that's based on a legitimate driver. But in the case of Poison X, it appears to have been developed as a malicious tool from what we can see and obviously the developer says it was developed as a research tool
Starting point is 00:08:23 but from what our analysts can see it's only ever been used for kind of malicious purposes so it does appear that in this case the developers of it were able to somehow trick or convince Microsoft to sign the driver
Starting point is 00:08:38 we're not obviously entirely sure how they achieve that but that obviously just make it quite dangerous it's also a little bit more unusual because as I say normally we do see these legitimate drivers kind of being exploited as opposed to these specifically malicious drivers being used by attackers.
Starting point is 00:08:55 I mean, we have seen the driver's poor try is one that we see frequently being used as well, which similarly also appears a bit of malicious driver that the developer somehow managed to get signed, but we don't really know how exactly they are managing to do that. I want to touch on their attempts to evade detection here. You mentioned that
Starting point is 00:09:16 they disguised one of their tools as a semantic product. What do you suppose the purpose of that was? What did they achieve through that? Well, they just disguised it in the sense of the name of the two, which was semantic.exe. And I suppose we're just trying to disguise it to masquerade it, I suppose, alongside other, because obviously this, this is one of us, one of our customers.
Starting point is 00:09:38 So they obviously have semantic, you know, software on their machines. So I guess they were just kind of blend in with the legitimate, software and trying to make that kind of connections back to their server and all that look like legitimate traffic as much as possible. And I mean, this is something we see, you know, all the time really with attackers that they're kind of nowadays constantly trying to use, even using legitimate cloud services and using legitimate tools in general, in order to try and blend into that legitimate traffic that's on machines because then it just obviously makes it makes things so much harder to detect when attackers are using these legitimate tools.
Starting point is 00:10:18 They do have legitimate uses, but obviously just using them for malicious purposes. And then so we often see that then as well. Whereas obviously this was a malicious tool, but they were trying to masquerade and ask legitimate by giving it the semantic name. And what security tools were they out to disable? So they were basically out to disable whatever security tools were on. So they would use the Poison X driver to basically terminate, terminate, security processes were on the system, including the endpoint detection and response products
Starting point is 00:10:49 as well. And they're able to do this because of the nature of drivers, because drivers basically have kernel access, which allows them to delete or stop or throttle, I suppose, security products in a way that other tools, you know, aren't able to do, basically. Because these drivers have this hurdle level access, they have a level of access and a level of capability to stop other tools that, you know, other tools that are just at the user level can't achieve. So this is why, you know, we've seen this growth in B-Y-O-V-D and why it's such a popular tactic now for, you know,
Starting point is 00:11:36 ransomware actors and threat actors in general who wants to say, security tools and then, you know, I guess make their, make their activity essentially invisible that on the victim network once those tools are disabled a lot of the time. We'll be right back. A component of this was their lateral movement. Can you walk us through what they were doing there? Yeah, so what is interesting actually with this group Hyatina, they're very, since the start, even since they, I suppose, first came out as monster and then when they were beasts as well.
Starting point is 00:12:18 and now with Goddam, they're very focused on deploying a lot of password seeding, prudential harvesting tools. And that seems to be a big part of their attack. So we see them in this tool using mimicats and then also using a whole suite of basically password sealing tools that are kind of developed by NIRSoft. So they're kind of these publicly available. It's publicly available tool kit, really, that can kind of harvest credentials from everywhere, really, you know, like all your different apps.
Starting point is 00:12:48 your browsers, all that. So that's a big part of their operations as well, is stealing all those credentials in order to help them move across the system, basically, and move across the network. So they did that. They downloaded a lot of these tools. And then they had a little gap of activity
Starting point is 00:13:08 probably while they were sort of, I suppose, you know, coordinating all these credentials. And then lateral movement began across the network at that point. and they used yes they again again using logitimate tools as well
Starting point is 00:13:23 for this activity they use PSXX for lateral movement and they also launched admin shares with using the stonal credentials as well they were able
Starting point is 00:13:33 to disable Windows defender monitoring as well and then they used anidesk which they deployed then based on each host that they were able to
Starting point is 00:13:41 reach in order to maintain that kind of persistent access they registered as an auto start service so that they could maintain that persistent access even if the computers were rebooted or that kind of thing. They were still able to maintain that access. So that was a key part of their activity as well. And I think, you know, it's interesting that certain parts of, I suppose, the group's activity has changed. Obviously, while they're rebranding with the different
Starting point is 00:14:12 names and stuff, a lot of their other steps of their attack has remained very. similar because they're used of antithereuse these prudential harvesting tools, that has kind of remained a fairly consistent step in their attacks that we've seen them carrying out, even since they were carrying out the monster attacks as well. How much of this is actually new compared to the Beast ransomware? I think their use of Poison X is quite interesting. We didn't see them use to BYOVD element previously in the attacks. Like the monster attacks,
Starting point is 00:14:50 we saw them very much kind of exploit using all the kind of living off the land and probably the available tools and that kind of thing. And similarly with Beast, we did see them start to use some other tools. They were using the Gmer tool
Starting point is 00:15:01 which can be kind of used for stopping processes and things like that as well. But their use of Poison X, I think, does, you know, kind of constitute a bit of a step up, I think, and their sophistication, really. it's quite a new tool, it's Poison X one.
Starting point is 00:15:18 It hasn't been used very widely. It's only relatively recently newly discovered. So it just seems to be a bit of an escalation in their defensive agent capability and even the use obviously of the BYU-OVD technique in general is a bit of an escalation in their defensive agent capabilities really as well. So I think that is interesting and it kind of shows
Starting point is 00:15:39 they're obviously continuing to kind of adapt, to continue to develop their skills and develop the effectiveness of their attacks as much as possible. And so that's always something to keep an eye on, I think, with these groups, you know, that they're obviously once they're continuing to try and keep these attacks stealthy and make them as effective as possible on their side of things, I think is always worth keeping an eye on. What are your recommendations then for the security professionals in our audience to best protect their organizations here? I mean, I think the steps are quite, similar really when it comes to protecting companies that are from ransomware for all groups really
Starting point is 00:16:17 you know companies need to have that good security software and those kind of typical mitigation steps in place with that kind of high priority on alerts that trigger on ransomware and pre-ransomor activity you know as those enterprise why the tax can happen very quickly now we actually published a blog just last week or the week before as well since we published this blog about a seemingly new ransomware called spirals and that went from you know the first activity being seen on the network to the ransom being deployed within 24 hours. So that was a very, that escalated very quickly that attack. I mean, the goddamn attack was took place over four days, which is also relatively quick as well. So I think that, you know, having those alerts for that
Starting point is 00:16:58 pre-ransomware activity is definitely really important as these attacks kind of speed up in lots of ways. And I think obviously though it wasn't a factor in those particular attacks as AI becomes increasingly adopted by threat actors and ransomware actors, you know, inevitably probably the speed of attacks is only likely to increase, you know. And I guess then for general sense, you know, for all organisations, I need that kind of defence in-depth strategy, having those kind of multiple detection and protection, different technologies as well to help mitigate risk at different points. It's that behavioural technology is important as well now, I think, because as we say, the use of so many legitimate tools and that kind of thing.
Starting point is 00:17:40 And, you know, so they make sure that all parts of their secure day, I guess, are enabled and working together to help detect the tax more quickly, you know, as well as monitoring things like the use of due to use tools inside their network. And then the kind of basic things of, you know, obviously controlling who has access to administrative accounts, multifactor authentication, multifactor authentication, all those kind of basic steps as well that are very important to try and keep network safe. When you look at this research, and you mentioned some of the other recent research that you and your colleagues have done, where do you suppose this is heading? What does the future of ransomware look like in your estimation?
Starting point is 00:18:19 That's a big question. I mean, it's hard to know. Like, ransomware really, you know, it's been so consistently around for such a long time. Now, you know, I think we have seen, obviously, changes and variations. we've seen a lot more of the extortion only attacks as well, becoming very popular, obviously with the attacker, with the groups like shiny hunters and things like that as well. So that ransomware itself isn't necessarily being deployed
Starting point is 00:18:46 in every attack we see. You know, we are seeing some attacks where the attackers are just stealing data and then trying to use that to extort companies. I think that will continue as a trend as well because I just think in lots of ways it's, you know, probably easier for attackers and sometimes just, it's effective. But I think when it comes to like a really, you know, a really successful ransomware attack for want to be a better word, you know, nothing can kind of compare to that when it comes
Starting point is 00:19:13 to the disruption that can be caused by the attackers and the kind of leverage that can give them, you know, particularly against organisations and, you know, the likes of healthcare or government or, you know, manufacturing or like kind of having that downtime is really going to damage an organisation. So I don't think ransomware is going to go anywhere. And I do think, inevitably, like we haven't really seen it yet. Obviously, we've seen AI use for, you know, certain things, you know, for lures, for phishing emails, for a certain amount of writing code and that kind of thing. But I'm sure as we go forward and as the technology continues to develop, we will see ransomware actors, you know, using AI probably trying to speed up these attacks and try to,
Starting point is 00:19:54 you know, deploy the ransomware even more quickly across the network, which does make it even more challenging for defenders and for security companies to protect against this kind of behaviour. So I think it's hard to know where things are going. But I suppose it's always a bit of a race between, I guess, defenders trying to use new technologies to improve things for people. But then, unfortunately, attackers also being able to use these new technologies to, you know, make their attacks more effective as well. So I think it's an ever-changing, an ever-changing landscape. But I definitely think ransomware will be around for the foreseeable few. future on anyway for sure.
Starting point is 00:20:33 Our thanks to Bridget O'Gorman from Symantec for joining us. The research is titled GD Ransomware. Latest Beast rebrand uses malicious driver to disable defenses. We'll have a link in the show notes. And that's Research Saturday, brought to you by N2K Cyberwire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
Starting point is 00:21:09 If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey and the show notes or send an email to Cyberwire at n2k.com. This episode was produced by Liz Stokes. We're mixed by Elliot Peltzman and Trey Hester. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here next time.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.