Intrusions weaponizing searches for illicit tax-related documents to spread trojanized ConnectWise ScreenConnect installers that facilitate a bring your own vulnerable driver attack have been launched against individuals across the U.S. as part of a widespread malvertising campaign that has been underway since January, The Hacker News reports.
Threat actors exploited Google Ads to serve sponsored results for "W2 tax form" or W-9 Tax Forms 2026" searches, which redirect to fake sites protected by an Adspect-powered PHP-based Traffic Distribution System to enable the clandestine delivery of the ScreenConnect installers, according to a Huntress analysis.
After being used to launch various trial instances on the targeted device, ScreenConnect is later harnessed to inject a multi-stage crypter that facilitates the deployment of the HwAudKiller EDR killer. HwAudKiller exploits a vulnerable Huawei driver to then end Microsoft Defender, SentinelOne, and Kaspersky-related processes.
"This campaign illustrates how commodity tooling has lowered the barrier for sophisticated attacks," said Huntress researcher Anna Pham.
Threat actors exploited Google Ads to serve sponsored results for "W2 tax form" or W-9 Tax Forms 2026" searches, which redirect to fake sites protected by an Adspect-powered PHP-based Traffic Distribution System to enable the clandestine delivery of the ScreenConnect installers, according to a Huntress analysis.
After being used to launch various trial instances on the targeted device, ScreenConnect is later harnessed to inject a multi-stage crypter that facilitates the deployment of the HwAudKiller EDR killer. HwAudKiller exploits a vulnerable Huawei driver to then end Microsoft Defender, SentinelOne, and Kaspersky-related processes.
"This campaign illustrates how commodity tooling has lowered the barrier for sophisticated attacks," said Huntress researcher Anna Pham.




