A large-scale malvertising campaign used Google Ads and fake tax-form websites to target U.S. users searching for W-2 and W-9 documents, redirecting victims through domains such as anukitax[.]com and bringetax[.]com to download a rogue ScreenConnect MSI. Huntress said the activity has been active since at least January 2026 and identified more than 60 rogue ScreenConnect sessions across its customer base. The operation used cloaking services including Adspect and JustCloakIt to evade ad reviewers and researchers, and the same infrastructure also supported a fake Google Chrome update lure.
After gaining remote access, the attackers deployed the FatMalloc crypter, installed FleetDeck for redundant persistence, and launched HwAudKiller, a bring-your-own-vulnerable-driver tool that abused a signed Huawei audio driver to terminate security products from kernel mode. Huntress reported the malware disabled defenses including Windows Defender, Kaspersky, and SentinelOne, then dumped LSASS credentials and used NetExec for account harvesting across victim networks. The intrusion pattern was assessed as consistent with ransomware staging or initial access brokerage, and exposed infrastructure containing Russian-language JavaScript comments and Telegram-based victim notifications suggested a broader toolkit operated by a likely Russian-speaking developer.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
On March 19, 2026, Huntress publicly documented the tax-themed malvertising operation, including its use of Adspect and JustCloakIt for cloaking, the FatMalloc crypter, and the HwAudKiller EDR killer. The report also noted fake Chrome update lures, Telegram-based victim notifications, shared 4sync infrastructure, and Russian-language code comments suggesting a likely Russian-speaking developer.
Across its customer base, Huntress identified more than 60 rogue ScreenConnect sessions associated with the campaign, often with redundant relays and FleetDeck persistence. In at least one intrusion, the attackers disabled products including Windows Defender, Kaspersky, and SentinelOne, dumped LSASS credentials, and used NetExec for account harvesting, behavior consistent with ransomware staging or initial access brokerage.
Victims who followed the tax-themed lures were redirected through domains such as anukitax[.]com and bringetax[.]com to install a rogue ScreenConnect MSI, giving attackers remote access. The intrusion chain then deployed FatMalloc, FleetDeck, and HwAudKiller, a BYOVD payload abusing a signed Huawei audio driver to terminate security tools from kernel mode.
By at least January 2026, a large-scale campaign was active that targeted U.S. users searching Google for W-2 and W-9 tax forms. The operation used Google Ads, cloaking services, and fake tax-themed websites to redirect victims toward malicious downloads.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.