Ransomware, Malware, Threat Intelligence

Trojanized ConnectWise ScreenConnect installers deployed in tax-themed malvertising campaign

Digital warning signs: A digital landscape, with warning signs on the screen, which depicts an alert or error.

Intrusions weaponizing searches for illicit tax-related documents to spread trojanized ConnectWise ScreenConnect installers that facilitate a bring your own vulnerable driver attack have been launched against individuals across the U.S. as part of a widespread malvertising campaign that has been underway since January, The Hacker News reports.

Threat actors exploited Google Ads to serve sponsored results for "W2 tax form" or W-9 Tax Forms 2026" searches, which redirect to fake sites protected by an Adspect-powered PHP-based Traffic Distribution System to enable the clandestine delivery of the ScreenConnect installers, according to a Huntress analysis.

After being used to launch various trial instances on the targeted device, ScreenConnect is later harnessed to inject a multi-stage crypter that facilitates the deployment of the HwAudKiller EDR killer. HwAudKiller exploits a vulnerable Huawei driver to then end Microsoft Defender, SentinelOne, and Kaspersky-related processes.

"This campaign illustrates how commodity tooling has lowered the barrier for sophisticated attacks," said Huntress researcher Anna Pham.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds