Hyadina

MISP
Type:
Unknown
Country:
Unknown
First seen:
Unknown
Details:

Hyadina is a threat actor that first emerged in March 2022, deploying its Monster ransomware variant primarily targeting 32-bit Windows systems while avoiding the CIS region. The group rebranded its ransomware as Beast in June 2024, enhancing its toolset to include support for Linux and VMware ESXi, and incorporating extensive use of NirSoft tools. The latest iteration, GodDamn, showcases advanced defensive evasion techniques, including the use of the PoisonX malicious driver component. Hyadina operates as a ransomware-as-a-service, collaborating with affiliates to execute attacks.

Metadata
ID: 1097
Created: 27/07/2026 16:00
Updated: 11/09/2026 04:00