CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

How a Tax Search Leads to Kernel-Mode AV/EDR Kill

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 731

As cited

Copy frozen at (site build).

threat intel

How a Tax Search Leads to Kernel-Mode AV/EDR Kill

Huntress identified a malvertising campaign themed around tax season that uses Google Ads and cloaking techniques to distribute rogue ScreenConnect remote access software. The attackers employ an undocumented Huawei driver to disable antivirus and endpoint detection and response (EDR) security tools at the kernel level.

Why it matters: Organizations and employees using legitimate search tools are at risk of landing on malicious tax-themed ads that install remote access and disable security protections, exposing systems to further compromise. Security teams need to monitor for compromised endpoints running unauthorized ScreenConnect instances and watch for exploitation of kernel-level driver vulnerabilities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

How a Tax Search Leads to Kernel-Mode AV/EDR Kill

Huntress identified a malvertising campaign themed around tax season that uses Google Ads and cloaking techniques to distribute rogue ScreenConnect remote access software. The attackers employ an undocumented Huawei driver to disable antivirus and endpoint detection and response (EDR) security tools at the kernel level.

Why it matters: Organizations and employees using legitimate search tools are at risk of landing on malicious tax-themed ads that install remote access and disable security protections, exposing systems to further compromise. Security teams need to monitor for compromised endpoints running unauthorized ScreenConnect instances and watch for exploitation of kernel-level driver vulnerabilities.

VendorsGoogleConnectWise
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary