Tax Scam Google Ads Push BYOVD EDR Killer, Huntress Finds
ID: aa189d43-d93a-5ec4-97e8-7f9b08d97e1f
STIX ID: report--aa189d43-d93a-5ec4-97e8-7f9b08d97e1f
Feed Name: GBHackers
A Huntress investigation documents an active malvertising campaign that delivered rogue ScreenConnect remote-access installers via sponsored Google Ads (tax- and browser-update-themed). The payload chain uses a MinGW crypter (FatMalloc) to load HwAudKiller, a BYOVD memory-resident tool that leverages a signed Huawei audio driver to terminate EDR/AV from kernel mode, after which intruders performed LSASS dumps, credential harvesting, and lateral movement — indicating significant operational maturity and immediate risk to affected environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
