Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR

A large-scale malvertising campaign targets users searching for tax documents to deploy ScreenConnect malware and a specialized EDR killer tool. The attack leverages a vulnerable Huawei driver to bypass security protections and gain persistent access.
A large-scale malvertising campaign active since January 2026 has been observed targeting U.S.-based individuals searching for tax-related documents to serve rogue installers for ConnectWise ScreenConnect that drop a tool named HwAudKiller to blind security programs using the bring your own vulnerable driver (BYOVD) technique.
Abuse of Google Ads and Sophisticated Cloaking
According to Huntress researcher Anna Pham, the campaign abuses Google Ads to serve rogue ScreenConnect (ConnectWise Control) installers. The attack begins when users search for terms like "W2 tax form" or "W-9 Tax Forms 2026," tricking them into clicking sponsored results that lead to bogus sites.
To evade detection, the threat actors employ commercial cloaking services like Adspect and JustCloakIt. A PHP-based Traffic Distribution System (TDS) generates a fingerprint of the visitor to ensure that security scanners see a benign page, while only real victims are served the malicious payload.
Blinding EDR with Huawei Drivers
The most striking feature of this campaign is the use of HwAudKiller to disable Endpoint Detection and Response (EDR) solutions. The tool leverages a legitimate, signed Huawei kernel driver, HWAuidoOs2Ec.sys, designed for laptop audio hardware.
Because the driver is legitimately signed, Windows loads it despite Driver Signature Enforcement (DSE). Once loaded, the driver terminates processes associated with Microsoft Defender, Kaspersky, and SentinelOne from kernel mode, bypassing usermode protections. Additionally, the malware attempts to evade emulators by allocating 2GB of memory, causing resource-heavy analysis tools to fail.
Objectives: Ransomware and Access Brokering
Huntress identified over 60 instances of malicious sessions tied to this campaign. Once security tools are disabled, the actors dump credentials from the LSASS process and use tools like NetExec for network reconnaissance and lateral movement.
These tactics align with pre-ransomware behavior or initial access broker activity. While the exact attribution is unknown, an exposed directory in the infrastructure revealed JavaScript code with Russian-language comments, suggesting a Russian-speaking developer is involved.
This campaign illustrates how commodity tooling has lowered the barrier for sophisticated attacks, combining commercially available cloaking, free-tier remote management tools, and signed drivers with exploitable weaknesses to build an effective end-to-end kill chain.
Source: The Hacker News
















