Episode

A beast by any other name. [Research Saturday]

Podcast
CyberWire Daily
Published
Sep 12, 2026
Duration seconds
1382
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/441/notes
Audio
https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW1411726251.mp3
JSON
/v1/public/podcasts/cyberwire-daily-454880/episodes/a-beast-by-any-other-name-research-saturday
Markdown
/podcast/cyberwire-daily-454880/a-beast-by-any-other-name-research-saturday.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/a-beast-by-any-other-name-research-saturday/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/cyberwire-daily-454880/a-beast-by-any-other-name-research-saturday.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques to evade defenses. In a recent attack, the threat actors used AnyDesk for remote access, a broad credential-harvesting toolkit, and the PoisonX malicious kernel driver to disable endpoint security before deploying the ransomware. The activity highlights Hyadina’s continued development of its ransomware operations and an escalation in its defense-evasion capabilities. The research and executive brief can be found here: ⁠⁠⁠⁠GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses Learn more about your ad choices. Visit megaphone.fm/adchoices