Hyadina is a Ransomware-as-a-Service group active since 2022, known for Monster, Beast, and GodDamn ransomware variants.
Analyst brief
Hyadina is a Ransomware-as-a-Service group active since March 2022, deploying Monster, Beast, and GodDamn ransomware variants. Initially targeting 32-bit Windows systems, it expanded to Linux and VMware ESXi with the Beast version while avoiding the CIS region. Key TTPs include extensive use of NirSoft tools, advanced defensive evasion via the PoisonX malicious driver in the GodDamn variant, and collaboration with affiliates for customized attacks. Defenders should update detection rules for abused NirSoft utilities, actively monitor Linux/ESXi environments, add signatures for Bring Your Own Vulnerable Driver (BYOVD) attacks, and strengthen network segmentation.
Hyadina
unknown
Hyadina is a threat actor that first emerged in March 2022, deploying its Monster ransomware variant primarily targeting 32-bit Windows systems while avoiding the CIS region. The group rebranded its ransomware as Beast in June 2024, enhancing its toolset to include support for Linux and VMware ESXi, and incorporating extensive use of NirSoft tools. The latest iteration, GodDamn, showcases advanced defensive evasion techniques, including the use of the PoisonX malicious driver component. Hyadina operates as a ransomware-as-a-service, collaborating with affiliates to execute attacks.