logo

Tax Scam Google Ads Push BYOVD EDR Killer, Huntress Finds

ID: aa189d43-d93a-5ec4-97e8-7f9b08d97e1f

STIX ID: report--aa189d43-d93a-5ec4-97e8-7f9b08d97e1f

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A Huntress investigation documents an active malvertising campaign that delivered rogue ScreenConnect remote-access installers via sponsored Google Ads (tax- and browser-update-themed). The payload chain uses a MinGW crypter (FatMalloc) to load HwAudKiller, a BYOVD memory-resident tool that leverages a signed Huawei audio driver to terminate EDR/AV from kernel mode, after which intruders performed LSASS dumps, credential harvesting, and lateral movement — indicating significant operational maturity and immediate risk to affected environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.