Huntress researchers uncovered a large-scale tax-themed malvertising campaign active since January 2026, targeting U.S. users searching for W-2 and W-9 forms via Google Ads. The attack chain uses dual commercial cloaking services (Adspect and JustCloakIt) to evade detection, delivers rogue ScreenConnect installers, and ultimately deploys a BYOVD EDR killer called HwAudKiller. The tool abuses a previously undocumented, legitimately signed Huawei audio driver (HWAuidoOs2Ec.sys) to terminate Windows Defender, Kaspersky, and SentinelOne processes from kernel mode. A multi-stage crypter named FatMalloc evades AV using a 2GB memory allocation trick and indirect shellcode execution via timeSetEvent callbacks. Post-EDR-kill activity includes LSASS credential dumping and mass lateral credential harvesting with NetExec, consistent with a pre-ransomware or initial access broker playbook. Russian-language JavaScript comments in a fake Chrome update page on the same infrastructure suggest a Russian-speaking developer. YARA rules and full IoCs are provided.