As cited
Copy frozen at (site build).
ransomware
New Ransomware Exploits Malicious Driver to Remove Cybersecurity Protections
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
New Ransomware Exploits Malicious Driver to Remove Cybersecurity Protections
GodDamn ransomware leverages a remote desktop application to move laterally within networks and deploy the PoisonX kernel driver, which disables endpoint security controls. The malware combines network propagation with targeted driver installation to compromise defenders and facilitate encryption operations.
Why it matters: Organizations running affected remote desktop software face rapid ransomware deployment with disabled security tools; security teams should hunt for PoisonX driver artifacts and lateral movement patterns using remote desktop logs.
- Source published
- First seen by Cybersecurity Tracker