logo

Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR

ID: ec07eda3-38df-5b0c-b5d9-5e045f64179a

STIX ID: report--ec07eda3-38df-5b0c-b5d9-5e045f64179a

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-03-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A malvertising campaign active since January 2026 abuses Google Ads and layered commercial cloaking (Adspect and JustCloakIt) to deliver rogue ConnectWise ScreenConnect installers that drop a multi-stage crypter and an EDR-killer called HwAudKiller; the campaign leverages a legitimately signed Huawei audio kernel driver (HWAuidoOs2Ec.sys) to terminate security products in kernel mode, enabling LSASS credential dumps, lateral movement, and the deployment/stacking of additional RMM tools—observed in over 60 malicious ScreenConnect sessions and consistent with pre-ransomware or access brokerage activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.