logo

Tax-Themed Google Ads Lead to BYOVD EDR Killer in Huntress-Traced Malvertising Campaign

ID: 5881bb91-cee6-5384-ac34-a51cb6f7411e

STIX ID: report--5881bb91-cee6-5384-ac34-a51cb6f7411e

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A malvertising campaign using tax-themed Google Ads redirects victims to sites (anukitax.com → bringetax.com) that deliver a rogue ScreenConnect installer (form_w9.msi) to gain hands-on remote access; operators then run a crypter (FatMalloc) and deploy HwAudKiller which drops a Huawei-signed kernel driver (HWAuidoOs2Ec.sys → Havoc.sys) to terminate EDRs, dump LSASS credentials, and execute NetExec for credential harvesting—activity observed across 60+ sessions and likely supporting ransomware or access brokerage. Indicators include domains, filenames, the Huawei driver, and 4sync-hosted payloads; mitigations advised include downloading forms only from IRS.gov, allowlisting approved RMM tools, and monitoring Sysmon/event alerts for kernel driver creation and unsigned binaries executed from ScreenConnect paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.