How a Tax Search Leads to Kernel-Mode AV/EDR Kill
ID: b6eb8633-15b8-5a89-8aba-a915ea8f5b4e
STIX ID: report--b6eb8633-15b8-5a89-8aba-a915ea8f5b4e
Feed Name: Huntress Blog
A large-scale malvertising campaign abused Google Ads and layered cloaking (Adspect, JustCloakIt) to deliver rogue ScreenConnect installers hosted on 4sync; the installers ran a multi-stage crypter (FatMalloc) that loaded HwAudKiller, which leverages a legitimately signed Huawei audio driver (HWAuidoOs2Ec.sys / Havoc.sys) as a BYOVD to terminate EDR/AV from kernel mode, enabling LSASS dumping, mass credential harvesting, and further lateral compromise—report includes IoCs, YARA rules, and detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
