PULSE NAME
From W-2 to BYOVD: How a Tax Search Leads to Kernel-Mode AV/EDR Kill
WHITE dylanroth7 2026-03-20 Modified: 2026-03-20
25
IOCs
MEDIUM VOLUME
During retrospective threat hunting, the Huntress Tactical Response team recently uncovered a large-scale malvertising campaign that has been active since at least January 2026, targeting U.S.-based individuals searching for tax-related documents. The lures are specifically U.S. tax forms (W-2, W-9), and the fake landing pages reference IRS compliance, casting a wide net across employees, freelancers, contractors, and small businesses during filing season. The campaign abuses Google Ads to serve rogue ScreenConnect (ConnectWise Control) installers, ultimately delivering a BYOVD EDR killer that drops a kernel driver to blind security tools before further compromise. Across our customer base, we reported over 60 instances of rogue ScreenConnect sessions tied to this campaign being used as the initial access vector.
Indicators of Compromise (1 / 25 total)
All FileHash-SHA256 FileHash-SHA1 FileHash-MD5 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 eef8a950952696b018aa9c6da2f5d7ad 2026-03-20