Tax Scam Google Ads Push BYOVD EDR Killer, Huntress Finds
## Cybersecurity: Tax-themed Malvertising Campaign
Cybersecurity: Tax-themed Malvertising Campaign
Recent developments reveal that tax-themed Google Ads are being exploited to deploy a BYOVD-based EDR killer. Huntress has linked this malicious campaign to unauthorized ScreenConnect deployments, utilizing a vulnerable Huawei audio driver to bypass endpoint defenses prior to unauthorized system access.
Google Ads targeting tax-related searches such as “W2 tax form” and “W‑9 Tax Forms 2026” are redirecting users to deceptive landing pages designed to mimic IRS compliance. This tactic aims to deceive employees, contractors, and small businesses.
Huntress identified over 60 rogue ScreenConnect sessions associated with this campaign, establishing Google Ads as the primary access vector. The campaign employs domains like anukitax[.]com and bringetax[.]com to distribute a ScreenConnect MSI file, enabling unauthorized remote access.
The operation utilizes a dual-layer cloaking strategy to maintain ad visibility. Adspect and JustCloakIt (JCI) are employed for client and server-side cloaking, respectively. This setup allows malicious content to be served selectively, bypassing detection by Google reviewers and security scanners.
Recent developments reveal that tax-themed Google Ads are being exploited to deploy a BYOVD-based EDR killer.
On infected systems, the ScreenConnect session deploys a multi-stage crypter termed "FatMalloc." This crypter eventually loads HwAudKiller, a BYOVD tool leveraging a Huawei audio driver to disable various security processes from kernel mode.
This marks the first known instance of a Huawei audio driver being exploited as a BYOVD tool. The driver allows arbitrary process termination, granting attackers significant control over compromised systems. The malicious binary is signed by Huawei, facilitating its execution without raising security alerts.
Monitor for unexpected ScreenConnect instances, particularly those using trial parameters or default guest sessions. Inspect ScreenConnect working directories for unsigned executables exhibiting suspicious behavior. Alert on kernel services created from temporary directories as potential BYOVD attempts. Educate users on the risks of sponsored search results and encourage downloads only from official sites. Implement RMM allowlisting to approve known domains and tools, treating unapproved installations as potential compromises.
Based on reporting by GBHackers.
