Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Ads Lead to EDR-Disabling Malware via Huawei Driver

Malicious Ads Lead to EDR-Disabling Malware via Huawei Driver

Posted on March 24, 2026 By CWS

A recent surge in malicious advertising has been aimed at individuals in the United States searching for tax-related forms online. Since January 2026, these deceptive ads have been distributing compromised installers of ConnectWise ScreenConnect, which subsequently deploy a tool known as HwAudKiller. This tool effectively disables security programs by exploiting a Huawei driver vulnerability, a technique often referred to as bring your own vulnerable driver (BYOVD).

Campaign Details and Tactics

Huntress, a cybersecurity firm, reported that these ads exploit Google’s advertising platform to distribute rogue versions of ScreenConnect, which then drop a kernel driver to evade detection. Anna Pham, a researcher from Huntress, highlighted the use of commercial cloaking services to bypass security checks, employing an undocumented Huawei audio driver to neutralize security measures.

The campaign’s goals remain unclear, but evidence suggests that attackers may use this access to disable endpoint detection and response (EDR) tools and extract credentials from affected systems. Their methods indicate a potential pre-ransomware strategy or intentions to sell access to other cybercriminals.

Execution and Tools Employed

The attack initiates when users search for terms like “W2 tax form” on Google, leading them to fake sites through sponsored links. These sites, protected by Adspect’s cloaking services, present benign pages to security systems while delivering malware to actual users. This dual-layer protection is further enhanced by JustCloakIt’s server-side filtering.

Once users are deceived into downloading the compromised installer, it deploys multiple instances of ScreenConnect and additional tools like FleetDeck Agent, ensuring continued remote access. The main payload, HwAudKiller, leverages a Huawei driver to deactivate security software, including Microsoft Defender, by operating at the kernel level.

Technical Insights and Implications

The Huawei driver, “HWAuidoOs2Ec.sys,” is a legitimate component for audio hardware, but its exploitable nature allows it to terminate security processes from kernel space. This bypasses user-mode protections and exploits Windows’ driver signature enforcement.

Further analysis revealed an open directory containing code with Russian-language comments, hinting at a Russian-speaking developer. This suggests that the operation might be driven by individuals with access to common social engineering tools rather than state-level capabilities.

Conclusion and Future Outlook

This campaign exemplifies how readily available tools can enable complex cyberattacks. By combining commercial cloaking services, free-tier software instances, and a signed driver with vulnerabilities, attackers have crafted a sophisticated threat chain. The rapid deployment of multiple remote access tools on compromised systems further underscores the sophistication of these cybercriminals.

As the campaign continues, it highlights the need for enhanced vigilance and improved defenses against such evolving cyber threats. Organizations must remain proactive in updating security measures to counteract these innovative attack strategies.

The Hacker News Tags:BYOVD, Cyberattack, Cybersecurity, EDR, Google Ads, Huawei, Malvertising, Malware, ScreenConnect, Security

Post navigation

Previous Post: Israel Leverages Iran’s Surveillance for Strategic Advantage
Next Post: Enhanced Governance Critical for Securing AI Systems

Related Posts

ERMAC V3.0 Banking Trojan Source Code Leak Exposes Full Malware Infrastructure ERMAC V3.0 Banking Trojan Source Code Leak Exposes Full Malware Infrastructure The Hacker News
Opera GX Flaw Allowed Silent Mod Installs, Data Theft Opera GX Flaw Allowed Silent Mod Installs, Data Theft The Hacker News
Hackers Exploit Adform Script to Alter Crypto Wallets Hackers Exploit Adform Script to Alter Crypto Wallets The Hacker News
Charon Ransomware Hits Middle East Sectors Using APT-Level Evasion Tactics Charon Ransomware Hits Middle East Sectors Using APT-Level Evasion Tactics The Hacker News
New Windows Vulnerability PoC Released Post Patch Update New Windows Vulnerability PoC Released Post Patch Update The Hacker News
Cyber Attacks Leverage Fake Software Updates for Remote Access Cyber Attacks Leverage Fake Software Updates for Remote Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark