PULSE NAME
From W-2 to BYOVD: How a Tax Search Leads to Kernel-Mode AV/EDR Kill
WHITE dylanroth7 2026-03-20 Modified: 2026-03-20
25
IOCs
MEDIUM VOLUME
During retrospective threat hunting, the Huntress Tactical Response team recently uncovered a large-scale malvertising campaign that has been active since at least January 2026, targeting U.S.-based individuals searching for tax-related documents. The lures are specifically U.S. tax forms (W-2, W-9), and the fake landing pages reference IRS compliance, casting a wide net across employees, freelancers, contractors, and small businesses during filing season. The campaign abuses Google Ads to serve rogue ScreenConnect (ConnectWise Control) installers, ultimately delivering a BYOVD EDR killer that drops a kernel driver to blind security tools before further compromise. Across our customer base, we reported over 60 instances of rogue ScreenConnect sessions tied to this campaign being used as the initial access vector.
Indicators of Compromise (25)
All FileHash-SHA256 FileHash-SHA1 FileHash-MD5 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531 2026-03-20
FileHash-SHA1 0ded1a1eabec8ae0ffb0b512871e7b545878437a 2026-03-20
FileHash-MD5 eef8a950952696b018aa9c6da2f5d7ad 2026-03-20
FileHash-SHA1 1fa071303fb846308571e64727501fb98b1c2be6 2026-03-20
FileHash-SHA256 033f42102362a8d8d4bdba870599eb5e0c893d8fd8dd4bc2a4b446cbbeb59b99 2026-03-20
FileHash-SHA256 0821661e715fe64bb39f4fece277737a48fd6839edd40ec8a4a39bf04cea8524 2026-03-20
FileHash-SHA256 28278b8c85c832417f9860fe8ea3ddbb9ff1d5860317db4813227a3a52b7c7cc 2026-03-20
FileHash-SHA256 2b409a265f571dccde6ef4860831c1b03d5418d1951f97925315dc5b0891da04 2026-03-20
FileHash-SHA256 5abe477517f51d81061d2e69a9adebdcda80d36667d0afabe103fda4802d33db 2026-03-20
FileHash-SHA256 7509365935fc1bfadba20656698d3a29051031635419043bc2bc45116106e026 2026-03-20
URL http://anukitax.com/forminw9/ 2026-03-20
URL http://bringetax.com/humu/ 2026-03-20
URL http://grinvan.com/vims/browser/ 2026-03-20
URL http://rpc.adspect.net/v2/ 2026-03-20
URL https://jcibj.com/pcl.php 2026-03-20
domain anukitax.com 2026-03-20
domain bjtrck.com 2026-03-20
domain bringetax.com 2026-03-20
domain fioclouder.com 2026-03-20
domain friugrime.com 2026-03-20
domain grinvan.com 2026-03-20
domain gripsmonga.sbs 2026-03-20
hostname cdn.justcloakit.com 2026-03-20
hostname client.justcloakit.com 2026-03-20
hostname rpc.adspect.net 2026-03-20