CyberWire Daily - A beast by any other name. [Research Saturday]
Episode Date: September 12, 2026Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disabl...e Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques to evade defenses. In a recent attack, the threat actors used AnyDesk for remote access, a broad credential-harvesting toolkit, and the PoisonX malicious kernel driver to disable endpoint security before deploying the ransomware. The activity highlights Hyadina’s continued development of its ransomware operations and an escalation in its defense-evasion capabilities. The research and executive brief can be found here: GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Yes, you can have an enterprise network that's secure and reliable and high performance.
And no, you don't need to choose the best two out of three.
With meter, you can get the end-to-end network built from the ground up, fast to deploy, and easy to manage.
That's because meter is software-led for easy installation, maintenance, and control for everything running on your enterprise network.
Hardware, firmware, and software all working together from the start seamlessly on a unified platform that's secure by design.
You can't protect what you don't know exists, which is why meter gives you comprehensive visibility into wired and wireless routing, switching, firewalls, DNS security, and VPNs.
You'll really know what's running on your network down to the most granular client level.
Step off the hardware box upgrade treadmill and switch to the hardware.
to meter for a predictable fee and free up your team to spend time on all the other things that
keep your business running. Try it out for yourself and book a demo online at meter.com
slash cyberwire. That's M-E-T-E-R dot com slash cyberwire.
Hello everyone and welcome to the Cyberwires Research Saturday. I'm Dave Bittner,
and this is our weekly conversation with researchers and analysts tracking down the threats
and vulnerabilities, solving some of the hard problems and protecting ourselves in a rapidly evolving
cyberspace. Thanks for joining us. This is like a rather third rebrand that we're aware of.
So they had the monster ransomware that they started out with back in 2022. Then they rebranded to
Beast. And now they have Goddam. And also we've seen in some of their code as well, 666.
So they seem to have this kind of a beast, beastly, I suppose.
running through their ransomware names.
That's Bridget O'Gorman, senior intelligence analyst on the Semantec Threathunter team.
The research we're discussing today is titled GD Ransomware.
Latest Beast rebrand uses malicious driver to disable defenses.
I mean, I suppose, ransomware, well, threat actors in general have a bit of a history of, you know,
trying to be a little bit controversial sometimes with their names or with the kind of messes of even code and things like that.
So I guess they're carrying out a tradition in a way in that sense.
Do you suppose there's anything to be read into when a ransomware group continues to rebrand itself like this?
I mean, it's definitely not unusual for ransomware groups to rebrand.
I think generally it's in a way I suppose to take, sometimes it's trying to take the heat off of themselves, you know.
I mean, beast, monster, they would be sort of well-known enough.
names, but they wouldn't be hugely, I suppose, controversial ransomware brands. But in the past,
I think, we have seen, you know, other, other ransomware families rebrand in a situation where
maybe there's a lot of kind of pressure coming under them, maybe from law enforcement, maybe they've,
you know, done a particularly, a particularly controversial attack that maybe has put a lot of heat on them.
And so that can, you know, I suppose inspire them to rebrand.
I mean, we've seen a few examples of that in the past.
We saw the, you know, dark side ransomware,
which was using the colonial pipeline attack in the US,
which disrupted fuel supply on the East Coast back in 2020, 2020, 2021,
back in COVID times.
And I know that was hugely, you know, met a lot of headlines, very controversial.
And then that led to the group behind us who we trackers Corrieed.
they then rebranded to black matter after that.
And then they subsequently rebranded again to the noborous Black Cat Ransomber family,
which appears to be shut down at the moment.
But, you know, it's very possible they will come around again.
So I think rebranding is generally a way to try and maybe take a bit of the heat off of these ransomware families.
And sometimes I think maybe it can be driven as well if there's kind of fallouts,
perhaps between ransomware actors as well, and that maybe there can be kind of a, you know,
group that splits off and perhaps rebrands to a different identity.
as well. Well, let's walk through this attack from the beginning here. What are the first signs that
something is wrong? So the first sign we saw in this instance was there was suspicious
anodesk activity on the victim network, I suppose. We didn't see what the vector exactly used
was, so we don't know if they got in with phishing emails or if they got in by exploiting
vulnerabilities. The first kind of suspicious activity we saw was an antiske being installed.
on a computer in an unusual location
it was installed under the music folder
so that was kind of the first thing
that I suppose sparked a bit of
suspicion I guess in this attack
because it kind of indication
you know someone had
because it was in such an unusual location
that someone had gone in there
and kind of manually installed it as well
you know it wasn't even just
kind of automated installation
when it did something like that
and then we saw various connections
we made to AdiDesk
infrastructure
And then we saw the attackers starting to deploy their kind of defense evasion portion of their attack,
which was one of the interesting parts of this attack as well.
So part of that was that they downloaded onto the computer a defense evasion tool,
which they were masquerading as a semantic executable.
So they named this tool semantic.exe.
And that was also installed in the music folder and trying to impersonate semantic product.
though it didn't have any, you know, there was no legitimacy to that at all.
And then that was used to launch a kernel driver called Poison X.
So this was one of the interesting parts of this attack.
So I suppose BYOVD, as we call it, the bring your own vulnerable driver tactic.
It's something we're seeing so much now in ransomware attacks, like really increasingly
seeing, and we're seeing attackers use this BIOVD technique to disable security software most of the time.
that is what it is being used for.
And the Poison X driver that was used in this particular attack
is relatively kind of new on the scene.
I think it was first seen earlier on this year
where it was used in about April it was documented first.
And in that case it was used to disable crowd strike in an attack.
But this is, I believe, is the first time we've seen it used alongside a ransomware family as well.
Now, one of the things that caught my eye was
that driver was signed by Microsoft.
What's the significance of that?
I mean, it's significance, I suppose, in a few different ways.
You know, generally, most modern versions of Windows now,
drivers have to be signed or they won't be loaded.
So attackers always want, I suppose, to gain access to these signed drivers.
Now, generally what we see when attackers are using this B-Y-O-V-D technique
is they are basically exploiting of vulnerability.
in what is otherwise a legitimate driver
and using that then to basically kind of side load
or install their malware and their malicious activity
onto the victim network.
So, you know, we'd see things like that with ghost driver.
Like I'd say, that's kind of a publicly available tool
but that's based on a legitimate driver.
But in the case of Poison X, it appears to have been developed
as a malicious tool
from what we can see
and obviously the developer
says it was developed
as a research tool
but from what our analysts
can see it's only ever been used
for kind of malicious purposes
so it does appear that in this case
the developers of it
were able to somehow
trick or convince
Microsoft to sign the driver
we're not obviously entirely sure
how they achieve that
but that obviously just make it quite dangerous
it's also a little bit more unusual
because as I say normally
we do see these legitimate drivers kind of being exploited
as opposed to these
specifically malicious drivers being used by attackers.
I mean, we have seen the driver's poor try
is one that we see frequently being used as well,
which similarly also appears a bit of malicious driver
that the developer somehow managed to get signed,
but we don't really know how exactly they are
managing to do that.
I want to touch on their attempts to evade detection here.
You mentioned that
they disguised one of their tools as a semantic product.
What do you suppose the purpose of that was?
What did they achieve through that?
Well, they just disguised it in the sense of the name of the two,
which was semantic.exe.
And I suppose we're just trying to disguise it to masquerade it,
I suppose, alongside other, because obviously this,
this is one of us, one of our customers.
So they obviously have semantic, you know, software on their machines.
So I guess they were just kind of blend in with the legitimate,
software and trying to make that kind of connections back to their server and all that look
like legitimate traffic as much as possible. And I mean, this is something we see, you know,
all the time really with attackers that they're kind of nowadays constantly trying to use,
even using legitimate cloud services and using legitimate tools in general, in order to try
and blend into that legitimate traffic that's on machines because then it just obviously
makes it makes things so much harder to detect when attackers are using these legitimate tools.
They do have legitimate uses, but obviously just using them for malicious purposes.
And then so we often see that then as well.
Whereas obviously this was a malicious tool, but they were trying to masquerade and ask legitimate
by giving it the semantic name.
And what security tools were they out to disable?
So they were basically out to disable whatever security tools were on.
So they would use the Poison X driver to basically terminate, terminate,
security processes were on the system, including the endpoint detection and response products
as well. And they're able to do this because of the nature of drivers, because drivers basically
have kernel access, which allows them to delete or stop or throttle, I suppose, security products
in a way that other tools, you know, aren't able to do, basically.
Because these drivers have this hurdle level access,
they have a level of access and a level of capability to stop other tools
that, you know, other tools that are just at the user level can't achieve.
So this is why, you know, we've seen this growth in B-Y-O-V-D
and why it's such a popular tactic now for, you know,
ransomware actors and threat actors in general who wants to say,
security tools and then, you know, I guess make their, make their activity essentially invisible
that on the victim network once those tools are disabled a lot of the time.
We'll be right back.
A component of this was their lateral movement.
Can you walk us through what they were doing there?
Yeah, so what is interesting actually with this group Hyatina, they're very, since the start,
even since they, I suppose, first came out as monster and then when they were beasts as well.
and now with Goddam, they're very focused on deploying a lot of password seeding,
prudential harvesting tools.
And that seems to be a big part of their attack.
So we see them in this tool using mimicats and then also using a whole suite of basically
password sealing tools that are kind of developed by NIRSoft.
So they're kind of these publicly available.
It's publicly available tool kit, really, that can kind of harvest credentials from everywhere,
really, you know, like all your different apps.
your browsers, all that.
So that's a big part of their operations as well,
is stealing all those credentials
in order to help them move across the system, basically,
and move across the network.
So they did that.
They downloaded a lot of these tools.
And then they had a little gap of activity
probably while they were sort of, I suppose,
you know, coordinating all these credentials.
And then lateral movement began across the network at that point.
and they used
yes they again
again using
logitimate tools
as well
for this activity
they use PSXX for
lateral movement
and they also launched
admin shares
with using the
stonal credentials as well
they were able
to disable Windows
defender monitoring as well
and then they used
anidesk
which they deployed
then based on each
host that they were
able to
reach in order to
maintain that kind of
persistent access
they registered
as an auto start service so that they could maintain that persistent access even if the computers
were rebooted or that kind of thing. They were still able to maintain that access. So that was a key
part of their activity as well. And I think, you know, it's interesting that certain parts of, I
suppose, the group's activity has changed. Obviously, while they're rebranding with the different
names and stuff, a lot of their other steps of their attack has remained very.
similar because they're used of antithereuse these prudential harvesting tools, that has kind of
remained a fairly consistent step in their attacks that we've seen them carrying out, even since
they were carrying out the monster attacks as well.
How much of this is actually new compared to the Beast ransomware?
I think their use of Poison X is quite interesting. We didn't see them use to BYOVD
element previously in the attacks.
Like the monster attacks,
we saw them very much
kind of exploit using
all the kind of living off the land
and probably the available tools
and that kind of thing.
And similarly with Beast,
we did see them start to use some other tools.
They were using the Gmer tool
which can be kind of used for stopping processes
and things like that as well.
But their use of Poison X, I think,
does, you know, kind of constitute
a bit of a step up, I think,
and their sophistication, really.
it's quite a new tool,
it's Poison X one.
It hasn't been used very widely.
It's only relatively recently newly discovered.
So it just seems to be a bit of an escalation
in their defensive agent capability
and even the use obviously of the BYU-OVD technique in general
is a bit of an escalation in their
defensive agent capabilities really as well.
So I think that is interesting and it kind of shows
they're obviously continuing to kind of adapt,
to continue to develop their skills and develop the effectiveness of their attacks as much
as possible. And so that's always something to keep an eye on, I think, with these groups, you know,
that they're obviously once they're continuing to try and keep these attacks stealthy and make them
as effective as possible on their side of things, I think is always worth keeping an eye on.
What are your recommendations then for the security professionals in our audience to best protect
their organizations here? I mean, I think the steps are quite,
similar really when it comes to protecting companies that are from ransomware for all groups really
you know companies need to have that good security software and those kind of typical
mitigation steps in place with that kind of high priority on alerts that trigger on ransomware
and pre-ransomor activity you know as those enterprise why the tax can happen very quickly now
we actually published a blog just last week or the week before as well since we published this blog
about a seemingly new ransomware called spirals and that went from you know the first activity
being seen on the network to the ransom being deployed within 24 hours. So that was a very,
that escalated very quickly that attack. I mean, the goddamn attack was took place over four days,
which is also relatively quick as well. So I think that, you know, having those alerts for that
pre-ransomware activity is definitely really important as these attacks kind of speed up in lots of
ways. And I think obviously though it wasn't a factor in those particular attacks as AI becomes
increasingly adopted by threat actors and ransomware actors, you know, inevitably probably the
speed of attacks is only likely to increase, you know. And I guess then for general sense,
you know, for all organisations, I need that kind of defence in-depth strategy, having those kind
of multiple detection and protection, different technologies as well to help mitigate risk at
different points. It's that behavioural technology is important as well now, I think, because as we say,
the use of so many legitimate tools and that kind of thing.
And, you know, so they make sure that all parts of their secure day, I guess,
are enabled and working together to help detect the tax more quickly, you know,
as well as monitoring things like the use of due to use tools inside their network.
And then the kind of basic things of, you know, obviously controlling who has access
to administrative accounts, multifactor authentication, multifactor authentication,
all those kind of basic steps as well that are very important to try and keep network safe.
When you look at this research, and you mentioned some of the other recent research that you and your colleagues have done, where do you suppose this is heading?
What does the future of ransomware look like in your estimation?
That's a big question.
I mean, it's hard to know.
Like, ransomware really, you know, it's been so consistently around for such a long time.
Now, you know, I think we have seen, obviously, changes and variations.
we've seen a lot more of the extortion only attacks as well,
becoming very popular, obviously with the attacker,
with the groups like shiny hunters and things like that as well.
So that ransomware itself isn't necessarily being deployed
in every attack we see.
You know, we are seeing some attacks where the attackers are just stealing data
and then trying to use that to extort companies.
I think that will continue as a trend as well
because I just think in lots of ways it's, you know,
probably easier for attackers and sometimes just,
it's effective. But I think when it comes to like a really, you know, a really successful ransomware
attack for want to be a better word, you know, nothing can kind of compare to that when it comes
to the disruption that can be caused by the attackers and the kind of leverage that can give them,
you know, particularly against organisations and, you know, the likes of healthcare or government
or, you know, manufacturing or like kind of having that downtime is really going to damage an organisation.
So I don't think ransomware is going to go anywhere. And I do think,
inevitably, like we haven't really seen it yet. Obviously, we've seen AI use for, you know,
certain things, you know, for lures, for phishing emails, for a certain amount of writing code and that
kind of thing. But I'm sure as we go forward and as the technology continues to develop, we will
see ransomware actors, you know, using AI probably trying to speed up these attacks and try to,
you know, deploy the ransomware even more quickly across the network, which does make it even more
challenging for defenders and for security companies to protect against this kind of behaviour.
So I think it's hard to know where things are going. But I suppose it's always a bit of a race
between, I guess, defenders trying to use new technologies to improve things for people.
But then, unfortunately, attackers also being able to use these new technologies to, you know,
make their attacks more effective as well. So I think it's an ever-changing, an ever-changing landscape.
But I definitely think ransomware will be around for the foreseeable few.
future on anyway for sure.
Our thanks to Bridget O'Gorman from Symantec for joining us.
The research is titled GD Ransomware.
Latest Beast rebrand uses malicious driver to disable defenses.
We'll have a link in the show notes.
And that's Research Saturday, brought to you by N2K Cyberwire.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead
in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey and the show notes or send an email to Cyberwire at n2k.com.
This episode was produced by Liz Stokes.
We're mixed by Elliot Peltzman and Trey Hester.
Our executive producer is Jennifer Ibin.
Peter Kilpe is our publisher, and I'm Dave Bittner.
Thanks for listening.
We'll see you back here next time.
