As cited
Copy frozen at (site build).
ransomware
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
Security researchers identified a new ransomware family called GodDamn that uses a kernel driver called PoisonX to disable endpoint security software. The ransomware was first observed in May 2026 and is believed to be a rebranded variant of Beast ransomware.
Why it matters: Organizations running Windows endpoints need to detect and block this kernel driver before infection, as it directly undermines endpoint protection tools that would otherwise prevent or contain the attack.
- Source published
- First seen by Cybersecurity Tracker