Microsoft signed a malicious kernel driver, and now it's being used to kill security software in ransomware attacks.
July 9, 2026
A newly rebranded ransomware outfit is sneaking malware into American organizations using a malicious yet Microsoft-approved driver.
Researchers at Symantec recently observed a cyberattack from a group known as "Hyadina." Hyadina is a 4-year-old ransomware-as-a-service (RaaS) operation with a new locker, "GodDamn," an iteration on its previous lockers, "Beast" and "Monster." It typically attacks American organizations, and it also has a distinct distaste for former Soviet countries. Its targets have spanned sectors that include healthcare, manufacturing, education, and wherever else it finds opportunity.
In a recent case against an unidentified organization, Hyadina used a smorgasbord of dual-use hacking tools, including legitimate remote monitoring and management (RMM) software, and more than a dozen penetration testing programs. The real kicker, though, was a malicious program with kernel access on Windows, capable of killing any and all processes, including security software.










