GodDamn Ransomware Exploits Signed Driver to Kill Endpoint Defenses
The GodDamn ransomware leverages a Bring Your Own Vulnerable Driver (BYOVD) attack, abusing a Microsoft-signed kernel driver called PoisonX to disable endpoint detection and response (EDR) tools before deploying ransomware. Because the driver carries a legitimate Microsoft signature, traditional allowlisting controls may fail to block it at the kernel level. This technique is especially dangerous because it operates with ring-0 privileges, effectively blinding security tools before an attacker moves to encryption or lateral movement. The ransomware's rebrand from Beast also highlights how threat actors recycle and evolve tooling to evade signature-based detection, making behavioral and driver-level controls critical.
Tactical Insight
Immediate Actions
- Enable Microsoft's Vulnerable Driver Blocklist (HVCI / Memory Integrity) on all Windows endpoints to block known malicious or abused drivers.
- Audit and inventory all kernel drivers currently loaded across endpoints, flagging any unsigned or anomalously signed drivers.
- Apply the latest Windows security updates to ensure driver signature revocations are current.
Detection Measures
- Deploy behavioral EDR rules to alert on any process that attempts to load a kernel driver followed by termination of security processes.
- Monitor Windows Event Logs (Event ID 7045, 6) and Sysmon (Event ID 6) for unexpected driver load events, particularly from temporary or user-writable paths.
- Integrate threat intelligence feeds to receive timely updates on newly identified BYOVD drivers and add them to blocklists proactively.
Long-Term Improvements
- Enforce a strict application and driver allowlist policy using Windows Defender Application Control (WDAC) to prevent unauthorized kernel-mode code execution.
- Implement network segmentation so that a compromised endpoint cannot freely communicate laterally, limiting ransomware propagation.
- Establish a tested backup and recovery program with offline, immutable backups to ensure business continuity in the event ransomware encryption succeeds.