Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR
ID: ec07eda3-38df-5b0c-b5d9-5e045f64179a
STIX ID: report--ec07eda3-38df-5b0c-b5d9-5e045f64179a
Feed Name: The Hacker News
A malvertising campaign active since January 2026 abuses Google Ads and layered commercial cloaking (Adspect and JustCloakIt) to deliver rogue ConnectWise ScreenConnect installers that drop a multi-stage crypter and an EDR-killer called HwAudKiller; the campaign leverages a legitimately signed Huawei audio kernel driver (HWAuidoOs2Ec.sys) to terminate security products in kernel mode, enabling LSASS credential dumps, lateral movement, and the deployment/stacking of additional RMM tools—observed in over 60 malicious ScreenConnect sessions and consistent with pre-ransomware or access brokerage activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
