CSIRT Asobancaria warns on GodDamn ransomware
CSIRT Asobancaria detected a new GodDamn ransomware campaign using credential theft, remote access and system encryption.
CSIRT Asobancaria issued an alert on July 9, 2026, about a new GodDamn ransomware campaign that combines credential theft, remote access and system encryption. At the same time, A3Sec shared a LinkedIn post about a suspected ransomware case in Colombia's industrial supply chain, although that attribution remains unconfirmed.
CSIRT Asobancaria issued an alert on July 9, 2026, about a new GodDamn ransomware campaign that combines credential theft, remote access and system encryption. The warning describes a multi-stage operation designed to gain access to compromised environments before launching the encryption phase.
Techniques observed
According to the CSIRT notice, the campaign brings together three components: credential theft, remote access and system encryption. That sequence suggests the attacker is not just trying to lock files, but first to secure entry into the affected environment and then carry out encryption.
The alert does not provide, in the available material, additional details about the infrastructure used, the geographic scope of the campaign or the identities of specific victims. It does make clear that the focus is on the techniques used, not only on the final impact of the attack.
A3Sec post
At the same time, A3Sec shared a LinkedIn post titled "Presunto ataque de Ransomware en la cadena de suministro industrial de Colombia". According to that communication, its Cyber Threat Intelligence team detected the organization’s inclusion in a possible incident.
That reference should be treated with caution. The available material presents it as a presumption, not as official confirmation of an attack. For that reason, the attribution remains unverified in the information provided.
Together, the two items point to a regional ransomware scenario with potential impacts on organizations tied to industry in Colombia, although only the CSIRT Asobancaria alert is confirmed in the research material.
Sources
- Nueva campaña de GodDamn ransomware combina captura de credenciales, acceso remoto y cifrado de sistemascsirtasobancaria.com· CSIRT Asobancaria
- Publicación de A3Sec - LinkedInes.linkedin.com· A3Sec



