Google Ads tax-search ScreenConnect malvertising campaign
Campaign
Summary
Hide ▲
Show ▼
A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a path to initial access and follow-on compromise. The operation uses commercial cloaking and a BYOVD-based HwAudKiller tool to blind security defenses before deeper payloads run. Huntress tied over 60 malicious ScreenConnect sessions to the activity. Post-compromise actions included LSASS credential dumping and NetExec reconnaissance, suggesting pre-ransomware or initial access broker behavior.
Related Happenings
RedHook Android malware abuses Wireless ADB for shell access
Malware Activity
H score26
First: 12.07.2026 17:27
Last: 12.07.2026 17:27
Sources 1
About this happening:
The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedHook Android malware abuses Wireless ADB for shell access
Malware ActivityAbout this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
GodDamn ransomware PoisonX BYOVD activity
Malware Activity
H score14
First: 09.07.2026 13:43
Last: 09.07.2026 13:43
Sources 1
About this happening:
GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
GodDamn ransomware PoisonX BYOVD activity
Malware ActivityAbout this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
Major U.S. services company hit by ransomware attack linked to DragonForce
Incident
H score38
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
About this happening:
A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Major U.S. services company hit by ransomware attack linked to DragonForce
IncidentAbout this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware Activity
H score41
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware ActivityAbout this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware Activity
H score16
First: 28.05.2026 00:31
Last: 28.05.2026 00:31
Sources 1
About this happening:
A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware ActivityAbout this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
Timeline
-
24.03.2026 19:05 2 articles · 3mo ago
Google Ads tax-search ScreenConnect malvertising campaign disclosed
Initial DisclosureHuntress detailed a large-scale malvertising campaign active since January 2026 that used Google Ads and tax-themed search terms such as "W2 tax form" and "W-9 Tax Forms 2026" to steer U.S.-based users toward rogue ConnectWise ScreenConnect installers. The operation used Adspect and JustCloakIt cloaking, deployed a BYOVD EDR killer named HwAudKiller, and relied on the signed Huawei driver HWAuidoOs2Ec.sys to blind Microsoft Defender, Kaspersky, and SentinelOne before follow-on activity such as LSASS credential dumping and NetExec-based reconnaissance.
Show sources
- Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR — thehackernews.com — 24.03.2026 19:05
- Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR — thehackernews.com — 24.03.2026 19:05