Cybersecurity·5 min read

ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves. The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that c

CS
CyberShield Team
2026-07-20
Share:
ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves. The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that can receive dozens of instructions from its operators. The attack begins with a fake verification-style page that asks a visitor to copy and execute a command. That […] The post ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands appeared first on Cyber Security News.

A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves. The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that can receive dozens of instructions from its operators. The attack begins with a fake verification-style page that asks a visitor to copy and execute a command. That action downloads a VIDAR-based second stage, which then retrieves the TELEPUZ loader and its main payload, continuing a familiar pattern seen in recent ClickFix malware campaigns that turn user actions into initial access. Elastic said in a report shared with Cyber Security News (CSN) that TELEPUZ has been active since late April 2026 and appears to be developing quickly. Researchers observed regular uploads of new builds and a sharp increase in activity from early June, suggesting the operation is expanding. TELEPUZ infection chain (Source – Elastic) The malware is designed to stay small at first, then download extra features when needed. That approach lets operators add information-stealing, keystroke logging, browser manipulation, and other functions without placing every capability in the initial file. ClickFix Campaign Delivers Modular TELEPUZ Malware TELEPUZ communicates with its command-and-control server through WebSockets, using a JSON-based protocol to exchange information and receive tasks. It can repeatedly try its main server, then seek replacement infrastructure through Telegram, a Steam profile, DNS records, or a Polygon blockchain smart contract if contact fails. The 36 available commands give attackers broad control over an infected device. They include options to run commands, list files and processes, take screenshots, upload data, create ZIP archives, delete files, change the beacon interval, update the malware, and terminate jobs. TELEPUZ DownloadRunModule function downloading DLL (Source – Elastic) Several commands are built for credential theft and follow-on intrusion. TELEPUZ can retrieve a stealer module, start a keylogger, extract Chromium browser cookies, download other malware modules, and run executable files inside hollowed processes, placing it alongside threats that target browser credentials and cookies. The malware also includes a web-injection module that can interact with Chromium-based browsers and Firefox. Rather than relying solely on traditional browser code injection, the component can use browser debugging interfaces to intercept pages, execute JavaScript, manage rules, and potentially alter financial form fields. Evasion and Defensive Steps Before beginning normal activity, TELEPUZ checks whether it is running in a virtual machine, sandbox, debugger, or an excluded geographic region. It also uses encrypted strings, dynamic API lookups, indirect system calls, and patches designed to weaken Windows antimalware scanning and event tracing. For persistence, the malware can copy itself from temporary folders, relaunch through rundll32.exe, bypass User Account Control, steal higher-privileged access tokens, and register a Windows service. These steps can make a simple ClickFix mistake become a lasting compromise that is harder to investigate. TELEPUZ code showing ROR bit rotation operations (Source – Elastic) Organizations should train users never to paste commands from browser prompts into Run, Command Prompt, or PowerShell windows. Teams should also monitor unusual PowerShell and rundll32.exe activity, block listed indicators, use DNS and web filtering, and isolate suspected endpoints quickly, measures also recommended in coverage of multi-stage Vidar delivery. Security teams should treat browser-session theft as a priority after a confirmed infection. Reset exposed passwords, revoke active sessions, rotate privileged credentials, and review browser data, while endpoint monitoring should look for unusual module downloads and outbound WebSocket traffic, similar to activity described in WebSocket-enabled malware operations. Indicators of compromise (IoCs):- TypeIndicatorDescriptionURLhxxps://memshowblob[.]forum/api/index.php?a=grabClickFix-delivered second-stage download URLSHA-256580b441e2961739fd26e54e0a0ea08351cb10a51839519fc722cfa39ecd0c954VIDAR Go variantSHA-25603fa348b70819296c958c842e7646b3b7efe5fa217ed5098143003c47995a746TELEPUZ stagerDomainhurgadatour[.]shopTELEPUZ stager and payload hosting domainFile nameinstall.exeTELEPUZ stagerFile nametelepuz.dllTELEPUZ main payloadDomainchubrik[.]sbsStaging domainURLhxxps://chubrik[.]sbs/files/xK7mR9pL2nQw5tY8ygvfuyze.dllThird-stage payload URLDomainbetalegenda[.]cfdStaging domainURLhxxps://betalegenda[.]cfd/files/xK7mR9pL2nQw5tY8kmwvogwx.dllThird-stage payload URLDomainmavpaprokla[.]latStaging domainURLhxxps://mavpaprokla[.]lat/files/telemetriawork/telepuz.dllThird-stage payload URLDomaincomicstar[.]latStaging domainURLhxxps://comicstar[.]lat/files/telemetriawork/telepuz.dllThird-stage payload URLDomainbigblower[.]clickStaging domainURLhxxps://bigblower[.]click/files/telemetriawork/telepuz.dllThird-stage payload URLDomainmomasites[.]lolStaging domainURLhxxps://momasites[.]lol/files/telemetriawork/telepuz.dllThird-stage payload URLDomainmomasites[.]comStaging domainURLhxxps://momasites[.]com/files/telemetrywork/telepuzThird-stage payload URLDomainmamsites[.]lolStaging domainURLhxxps://mamsites[.]lol/files/telemetrywork/telepuz.dllThird-stage payload URLDomainhardenedom[.]shopStaging domainURLhxxps://hardenedom[.]shop/files/telemetriawork/telepuz.dllThird-stage payload URLDomainhardendedom[.]shopStaging domainURLhxxps://hardendedom[.]shop/files/lemetriawork/epuz.dllThird-stage payload URLDomainhardendom[.]shopStaging domainURLhxxps://hardendom[.]shop/files/telemetry/telepuz.dllThird-stage payload URLDomainhardeneddom[.]shopStaging domainURLhxxps://hardeneddom[.]shop/files/telemetrywork/telepuzThird-stage payload URLDomainnetblokirovka[.]asiaStaging domainURLhxxps://netblokirovka[.]asia/files/telemetriawork/telepuz.dllThird-stage payload URLDomainnetblokir[.]asiaStaging domainURLhxxps://netblokir[.]asia/files/telemetriawork/telepuz.dllThird-stage payload URLDomainnetlobikrovka[.]asiaStaging domainURLhxxps://netlobikrovka[.]asia/files/telemetriawork/telepuz.dllThird-stage payload URLDomainneblokirovka[.]asStaging domainURLhxxps://neblokirovka[.]as/telemetrynetwork/telepuz.dllThird-stage payload URLDomainkidsko[.]shopStaging domainURLhxxps://kidsko[.]shop/files/telemetriawork/telepuz.dllThird-stage payload URLDomainmazaporka[.]shopStaging domainURLhxxps://mazaporka[.]shop/files/telemetriawork/telepuz.dllThird-stage payload URLIP address172.67.215.214Staging infrastructure IPURLhxxps://172.67.215.214/files/telemetriawork/telepuz.dllThird-stage payload URLDomainkrabsburger[.]xyzStaging domainURLhxxp://krabsburger[.]xyz/files/telemetriawork/telepuz.dllThird-stage payload URLDomainzewaplus[.]clubPayload hosting domainURLhxxps://zewaplus[.]club/files/telemetriawork/telepuz.dllThird-stage payload URLIP address172.67.165.144Staging infrastructure IPURLhxxps://172.67.165.144/files/telemetriawork/telepuz.dllThird-stage payload URLDomaincal.joycedoula[.]com[.]brPrimary TELEPUZ command-and-control domainDomaincal.snehamumbai[.]orgFallback command-and-control domainTelegramt[.]me/chanadarkpartTelegram fallback C2 retrieval channelURLhxxps://steamcommunity[.]com/profiles/76561199705801219Steam profile used for fallback C2 retrievalDomaincodebasecode[.]comDNS-based fallback C2 lookup domainBlockchain address0xf55Bea1FdCf1c3ABb39ab92567C09aC1BFf6753EPolygon smart contract used for fallback C2 retrievalSHA-25658aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eedReference TELEPUZ main payloadSHA-256bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343TELEPUZ main payloadSHA-256ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3eTELEPUZ main payloadSHA-256a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3TELEPUZ keylogger moduleSHA-2569733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477ebTELEPUZ stealer moduleSHA-256444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1TELEPUZ web-injector moduleMutexcfgmgrmtxTELEPUZ mutexMutexbginfodmtxTELEPUZ mutexMutexwfj64mtxTELEPUZ mutexFile nameAppData.dllTELEPUZ persistence artifactFile nameProgramData.dllTELEPUZ installation artifactFile nameagent.dllTELEPUZ installation artifact Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now. The post ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands appeared first on Cyber Security News.

Share:

Join the Discussion

Comments coming soon. Follow us on social media for real-time discussions.