logo

How a Tax Search Leads to Kernel-Mode AV/EDR Kill

ID: b6eb8633-15b8-5a89-8aba-a915ea8f5b4e

STIX ID: report--b6eb8633-15b8-5a89-8aba-a915ea8f5b4e

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2026-03-19

Date Updated: 2026-04-28

...
...

A large-scale malvertising campaign abused Google Ads and layered cloaking (Adspect, JustCloakIt) to deliver rogue ScreenConnect installers hosted on 4sync; the installers ran a multi-stage crypter (FatMalloc) that loaded HwAudKiller, which leverages a legitimately signed Huawei audio driver (HWAuidoOs2Ec.sys / Havoc.sys) as a BYOVD to terminate EDR/AV from kernel mode, enabling LSASS dumping, mass credential harvesting, and further lateral compromise—report includes IoCs, YARA rules, and detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.