Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.


A ransomware group has built a weapon specifically designed to blind your security tools before striking. Here is what that means for your organisation.
Hyadina is a Ransomware-as-a-Service operation that has been active since 2022. In that time, it has cycled through three distinct malware payloads, each more capable than the last. Its latest, GodDamn, does something that should concern every executive: it disables endpoint security before the ransomware executes. By the time encryption begins, your defences are already down.
The group targets healthcare, manufacturing, and education organisations primarily across the United States and European Union. If your organisation operates in any of those sectors, this is a direct threat profile match.
Most ransomware relies on speed and volume. GodDamn relies on precision. It deploys a kernel-level driver called PoisonX, which carries a legitimate Microsoft signature, meaning operating systems treat it as trusted software. Once loaded, it systematically strips endpoint detection and response tools of their operating rights and terminates them entirely.
This is not a gap in your EDR configuration. It is a deliberate, technical dismantling of your security stack at the deepest level of the operating system. Standard detection logic does not catch it because the driver itself appears legitimate. Managed XDR services that maintain continuous, analyst-led visibility across endpoint, identity, and network telemetry provide a critical layer of defence where automated tooling alone will fail.
Hyadina affiliates use remote monitoring tools to establish persistence, most commonly AnyDesk. In observed GodDamn attacks, AnyDesk was installed in unexpected system locations and registered as a Windows service to survive reboots. This keeps attackers present across patch cycles and system restarts without triggering standard administrative alerts.
Credential theft follows quickly. Attackers deploy a suite of open-source tools to extract browser passwords, Active Directory hashes, and administrator credentials. The goal is domain-wide access before the ransomware payload is ever triggered.
Hyadina operates a double-extortion model. Encryption of your systems is only one half of the threat. Data exfiltrated before encryption is held as additional leverage. For organisations in regulated sectors, that means potential breach notification obligations, regulatory exposure, and reputational damage independent of whether you restore systems quickly.
The group has demonstrated consistent capability growth over four years. GodDamn is not a ceiling. It is a current iteration.
GodDamn represents a deliberate evolution in ransomware design, targeting the security stack itself as the first objective. Organisations that rely solely on EDR as their primary defence layer are most exposed. Layered controls at the kernel, identity, and application layer are no longer optional hardening measures. They are baseline requirements against this class of threat.
We protect your on-premise/cloud/OT environments - 24x7x365