Identity Fuels New Ransomware
Ransomware attacks are undergoing a significant transformation. Cybercriminals are increasingly abandoning traditional software exploits in favor of identity-based attacks, using stolen credentials and trusted tools to infiltrate networks. Two recent cybersecurity reports—one from Symantec and another from Sophos—highlight this growing trend, revealing that modern ransomware campaigns now focus on deception and defense evasion rather than brute-force exploitation.
Symantec's Threat Hunter Team recently uncovered a new ransomware family called GodDamn, first detected in May 2026. Rather than introducing sophisticated encryption techniques, the malware stands out for its ability to disable security protections before launching its ransomware payload. This strategy allows attackers to remain undetected while preparing systems for encryption and data theft.
At the heart of the campaign is PoisonX, a malicious kernel-level driver carrying a valid Microsoft digital signature. Unlike traditional "Bring Your Own Vulnerable Driver" (BYOVD) attacks that abuse legitimate drivers, PoisonX is believed to have been specifically created for malicious purposes while still obtaining a trusted signature. This enables it to bypass Windows security mechanisms and operate with elevated privileges.
During an attack investigated by Symantec, threat actors deployed PoisonX alongside a fake symantec.exe file to disable Microsoft Defender. They then leveraged tools such as PsExec and AnyDesk to move laterally across the network, establishing persistent access to multiple systems several days before deploying the ransomware. Researchers also found that PoisonX is now being shared among other ransomware groups, indicating wider adoption of this attack technique.
The broader picture emerges from Sophos' State of Ransomware 2026 report, based on responses from more than 2,100 organizations worldwide. For the first time in years, exploited vulnerabilities are no longer the leading cause of ransomware incidents. Instead, malicious emails, phishing attacks, and compromised credentials now account for the overwhelming majority of successful attacks, demonstrating that identity has become the primary target.
Equally concerning is the finding that 97% of organizations compromised through stolen credentials already had multi-factor authentication (MFA) enabled. This suggests attackers are increasingly bypassing MFA through phishing-resistant weaknesses, session hijacking, adversary-in-the-middle attacks, or incomplete deployment of stronger authentication methods such as FIDO2 security keys.
Together, the Symantec and Sophos findings reveal a common reality: attackers no longer need to break into systems when they can simply log in using trusted identities and disable security from within. Modern ransomware campaigns combine credential theft, legitimate administrative tools, and trusted software components to evade detection while operating as seemingly authorized users.
The message for defenders is clear. Vulnerability management and patching remain essential, but they are no longer enough. Organizations must strengthen identity security through phishing-resistant authentication, continuously monitor privileged access, detect unauthorized driver installations, restrict remote administration tools, and adopt behavioral analytics capable of identifying suspicious activity even when attackers appear to be legitimate users. In the identity era, trust itself has become the new attack surface.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




