GodDamn ransomware: a new BYOVD technique to bypass EDR and AV

Colleagues, I’d like to draw your attention to a cybersecurity development: the GodDamn ransomware group is using the PoisonX driver to disable endpoint protection.
According to Symantec, this group may be a rebrand of Beast and Monster. In the attack, they used AnyDesk for remote access, PsExec for lateral movement, and a credential theft tool.
The BYOVD approach is worth highlighting: a malicious but signed driver is loaded into the system and helps take AV/EDR offline or render them “blind”. The attackers also persisted via auto-start services.
Why this matters: these attacks show that defense must account not only for malicious files, but also for trusted yet vulnerable drivers, as well as control over remote access and lateral movement.
How do you strengthen BYOVD protection in your environment?
#cybersecurity #ransomware #EDR #BYOVD

