Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Tax Scam Google Ads Push BYOVD EDR Killer, Huntress Finds

## Cybersecurity: Tax-themed Malvertising Campaign

Cybersecurity: Tax-themed Malvertising Campaign

Recent developments reveal that tax-themed Google Ads are being exploited to deploy a BYOVD-based EDR killer. Huntress has linked this malicious campaign to unauthorized ScreenConnect deployments, utilizing a vulnerable Huawei audio driver to bypass endpoint defenses prior to unauthorized system access.

Google Ads targeting tax-related searches such as “W2 tax form” and “W‑9 Tax Forms 2026” are redirecting users to deceptive landing pages designed to mimic IRS compliance. This tactic aims to deceive employees, contractors, and small businesses.

Huntress identified over 60 rogue ScreenConnect sessions associated with this campaign, establishing Google Ads as the primary access vector. The campaign employs domains like anukitax[.]com and bringetax[.]com to distribute a ScreenConnect MSI file, enabling unauthorized remote access.

The operation utilizes a dual-layer cloaking strategy to maintain ad visibility. Adspect and JustCloakIt (JCI) are employed for client and server-side cloaking, respectively. This setup allows malicious content to be served selectively, bypassing detection by Google reviewers and security scanners.

Recent developments reveal that tax-themed Google Ads are being exploited to deploy a BYOVD-based EDR killer.
Emily Carter · Thehackingpost

On infected systems, the ScreenConnect session deploys a multi-stage crypter termed "FatMalloc." This crypter eventually loads HwAudKiller, a BYOVD tool leveraging a Huawei audio driver to disable various security processes from kernel mode.

This marks the first known instance of a Huawei audio driver being exploited as a BYOVD tool. The driver allows arbitrary process termination, granting attackers significant control over compromised systems. The malicious binary is signed by Huawei, facilitating its execution without raising security alerts.

Advertisement

Monitor for unexpected ScreenConnect instances, particularly those using trial parameters or default guest sessions. Inspect ScreenConnect working directories for unsigned executables exhibiting suspicious behavior. Alert on kernel services created from temporary directories as potential BYOVD attempts. Educate users on the risks of sponsored search results and encourage downloads only from official sites. Implement RMM allowlisting to approve known domains and tools, treating unapproved installations as potential compromises.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories