HwAudKiller is a Windows BYOVD-based EDR/AV killer used as the final payload in a large-scale malvertising campaign documented by Huntress and active since at least January 2026. In the observed intrusion chain, U.S.-based users searching Google for tax forms such as W-2 and W-9 were redirected through cloaked tax-themed sites to rogue ConnectWise ScreenConnect installers, which provided remote access and were then used to deploy a multi-stage crypter known as FatMalloc. FatMalloc ultimately unpacked and launched HwAudKiller.
HwAudKiller is designed to terminate security products from kernel mode by abusing a legitimate signed but vulnerable Huawei audio driver, HWAuidoOs2Ec.sys. The malware drops the driver to %TEMP% as Havoc.sys, creates a kernel service named Havoc, and uses the device \.\HWAudioX64 with IOCTL 0x2248DC to kill targeted processes. Reported targets include Microsoft Defender, Kaspersky, and SentinelOne; one Huntress fact extraction states it used ZwTerminateProcess from kernel mode to kill 23 targeted security processes. The embedded Huawei driver SHA256 is 5abe477517f51d81061d2e69a9adebdcda80d36667d0afabe103fda4802d33db, and the HwAudKiller payload SHA256 is 033f42102362a8d8d4bdba870599eb5e0c893d8fd8dd4bc2a4b446cbbeb59b99. Huntress stated this was the first documented public case of this Huawei audio driver being weaponized as a BYOVD tool.
HwAudKiller was associated with intrusions in which the threat actor also deployed multiple ScreenConnect relays and FleetDeck for persistence and redundancy. In at least one separate intrusion, a variant named sent.exe was followed by LSASS dumping via rundll32.exe and comsvcs.dll and credential harvesting across the network with NetExec, lsassy, and DPAPI-related modules, behavior Huntress assessed as consistent with pre-ransomware activity or initial access brokerage. Attribution remains unconfirmed, though exposed related infrastructure contained Russian-language JavaScript comments suggesting a likely Russian-speaking developer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The Slovakian cybersecurity company also called out the ransomware crew for its ability to "unusually quickly operationalize" newly disclosed proof-of-concept (PoC) exploits related to an attack technique called the bring your own vulnerable driver (BYOVD) technique, in many cases within days of their public release.
Starting at offset 0xF4 the shellcode is XOR-encrypted... The decoded shellcode resolves APIs by building strings character-by-character on the stack to evade static string detection.
These tools are standardized through a shared defense-evasion layer, impersonating predominantly security vendors using fake version information, and copied legitimate certificates and icons.
The shellcode then decrypts itself using a block-based XOR method before decompressing the final HwAudKiller payload into memory using LZNT1.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An EDR killer used to blind security tools by abusing a signed vulnerable Huawei kernel driver via the BYOVD technique, enabling termination of security processes from kernel mode before further compromise.
A kernel-mode security tool killer that drops a signed Huawei audio driver to disk as Havoc.sys, registers it as a kernel service, and uses it to terminate targeted security processes from kernel mode via IOCTLs, bypassing user-mode protections.
A user-mode BYOVD tool that decrypts and drops a signed Huawei audio driver as Havoc.sys, loads it as a kernel service, and repeatedly kills security product processes including Microsoft Defender, Kaspersky, SentinelOne, and in one variant FortiEDR.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.