
Since January 2026, a widespread ad-based malware operation has been observed targeting individuals in the U.S. searching for tax documents. This campaign uses fake installers for ConnectWise ScreenConnect to deploy a tool called HwAudKiller. This tool disables security software by exploiting a technique known as bring your own vulnerable driver (BYOVD).
“The campaign misuses Google Ads, serving malicious ScreenConnect (ConnectWise Control) installers, which then deliver a BYOVD EDR killer. This killer installs a kernel driver to disable security tools before further malicious activity,” Huntress researcher Anna Pham stated in a report released last week.
The security firm reported discovering over 60 instances of malicious ScreenConnect sessions related to the campaign. This attack is notable for a couple of reasons. Unlike recent attacks reported on by Microsoft that use tax-related lures, this campaign uses commercial cloaking services to avoid detection by security scanners and exploits a previously unknown Huawei audio driver to disable security measures.
The exact goals of the campaign are currently unclear. However, in one case, the attacker used the gained access to deploy the endpoint detection and response (EDR) killer and then steal login credentials from the Local Security Authority Subsystem Service (LSASS) process memory. They also used tools like NetExec for network exploration and lateral movement within the network.
Huntress suggests that these tactics are consistent with pre-ransomware activity or initial access broker behavior, indicating that the attacker intends to either deploy ransomware or sell the access to other cybercriminals.
The attack begins when users search for terms such as “W2 tax form” or “W-9 Tax Forms 2026” on search engines like Google. This tricks them into clicking on sponsored search results that lead to fake websites like “bringetax[.]com/humu/,” which then initiates the download of the ScreenConnect installer.
Furthermore, the landing page employs a PHP-based Traffic Distribution System (TDS) powered by Adspect, a commercial cloaking service. This ensures that a harmless page is displayed to security scanners and ad review systems, while only genuine targets are exposed to the actual malicious payload.
This is accomplished by generating a unique fingerprint of the site visitor and sending it to the Adspect backend, which then determines the appropriate response. In addition to Adspect, the landing page’s “index.php” also includes a second cloaking layer powered by JustCloakIt (JCI) on the server side.
“The two cloaking services are used together in the same index.phpâJCI’s server-side filtering runs first, and Adspect provides client-side JavaScript fingerprinting as a second layer,” Pham explained.
The web pages lead to the distribution of ScreenConnect installers, which are subsequently used to deploy multiple trial instances on the compromised host. The attacker has also been observed deploying additional Remote Monitoring and Management (RMM) tools such as FleetDeck Agent for redundancy and to ensure continued remote access.
The ScreenConnect session is used to deploy a multi-stage crypter, which then deploys an EDR killer called HwAudKiller. This uses the BYOVD technique to terminate processes related to Microsoft Defender, Kaspersky, and SentinelOne. The vulnerable driver used in the attack is “HWAuidoOs2Ec.sys,” a legitimate, signed Huawei kernel driver intended for laptop audio hardware.
“The driver terminates the target process from kernel mode, bypassing any user-mode protections that security products rely on. Because the driver is legitimately signed by Huawei, Windows loads it without issue despite Driver Signature Enforcement (DSE),” Huntress noted.
The crypter attempts to avoid detection by allocating 2GB of memory, filling it with zeros, and then freeing it. This effectively causes antivirus engines and emulators to fail due to excessive resource usage.
The identity of the attacker is currently unknown, but an exposed open directory in the attacker’s infrastructure revealed a fake Chrome update page containing JavaScript code with comments written in Russian. This suggests the involvement of a Russian-speaking developer who possesses a social engineering toolkit for malware distribution.
“This campaign shows how readily available tools can be used to carry out sophisticated attacks,” Pham said. “The attacker did not need custom exploits or nation-state capabilities. They combined commercially available cloaking services (Adspect and JustCloakIt), free ScreenConnect instances, an off-the-shelf crypter, and a signed Huawei driver with a flaw to create a full attack chain that goes from a Google search to kernel-mode EDR termination.”
“A consistent pattern across compromised hosts was the rapid installation of multiple remote access tools. After the initial malicious ScreenConnect connection was established, the attacker deployed additional trial ScreenConnect instances on the same endpoint, sometimes two or three within hours, and backup RMM tools such as FleetDeck.”
#ads #and #attack #bypass #detection #driver #edr #endpoint #huawei #leverages #malicious #malware #news #resembling #response #screenconnect #services #spread #tax #the — News
© Bulletproof Servers. All rights reserved.