daily cyber × ai intelligence

index

tagged

[poisonx]

1 edition · 1 item

July 10, 2026

  • GodDamn ransomware — assessed by Symantec's Threat Hunter Team as a rebrand of Beast — uses the PoisonX kernel driver to neutralize security software before encryption. Dark Reading notes the driver was Microsoft-signed and is being used to kill EDR in attacks against US companies, continuing the run of BYOVD abuse seen with The Gentlemen's Kontron driver last week. The Hacker News · Dark Reading · Malware & Endpoint Evasion

in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0