Back to all lessons
Awareness Lessons
7 months ago

Tax Season Malvertising Campaign Exploits User Trust and Legitimate Drivers

Cybercriminals exploited users' trust during tax season by creating convincing fake Google ads that appeared when searching for tax documents, leading to malicious ScreenConnect installations. The attack demonstrates how threat actors abuse legitimate signed drivers (in this case, Huawei's audio driver) to disable endpoint detection and response (EDR) systems through a technique called Bring Your Own Vulnerable Driver (BYOVD). This campaign highlights the dual threats of social engineering targeting seasonal needs and supply chain compromise through the misuse of legitimate software components to evade security controls.

Tactical Insight

Immediate actions

  • Organizations should implement comprehensive web filtering and DNS security solutions to block known malicious domains and suspicious redirects
  • EDR and antivirus solutions should be configured with driver attestation policies that prevent the loading of vulnerable or outdated signed drivers, and application control policies should restrict the installation of remote access tools like ScreenConnect to authorized personnel only

Long-term improvements

  • Security awareness training should emphasize the risks of clicking on search ads for sensitive activities like tax preparation, encouraging users to navigate directly to official websites

Detection measures

  • implementing network segmentation and monitoring for unusual outbound connections can help detect and contain such threats before they establish persistent access